RE: IP TCP Intercept question

From: Frank Jimenez (franjime@xxxxxxxxx)
Date: Thu Apr 11 2002 - 10:33:16 GMT-3


   
Trying to think outside of the box here...

If the inbound connection could be authenticated with some sort of AAA
session, then you could utilize the AAA server to give the connection a
hard timeout after xx minutes.

Could solve the real-life problem of people consuming sessions of some
scarce resource by logging in at 8AM and staying connected all day, even
if no work is being accomplished.

Frank Jimenez, CCIE #5738
franjime@cisco.com

Disclaimer:
These are my own personal opinions and not necessarily those of Cisco
Systems.

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
scott mann
Sent: Wednesday, April 10, 2002 2:24 PM
To: ccielab@groupstudy.com
Subject: IP TCP Intercept question

Can anyone tell me if using the below command will disconnect the
user/connection or simply cause the router to stop managing (keeping
stats
or control of) the user/connection. I want to disconnect the
user/connection
after a specific timeout period irregardless of his authentication/TCP
status.

"ip tcp intercept connection-timeout [seconds]"

Below is the Cisco Link, but it is not specific.

http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/
secur_c/scprt3/scddenl.htm

Thanks,
Lab in 2 days.



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:58:05 GMT-3