UDP Maximum Connection Limit
firewall (config)#
static (real_ifc,mapped_ifc) {mapped_ip | interface} {real_ip [netmask mask]} | {access-list access_list_name} [dns] [[tcp] [max_conns [emb_lim]] [norandomseq] ]] [udp udp_ma.x_conns]
firewall (config)#
nat {local_interface} nat_id local_ip [mask [dns] [outside] [[tcp] tcp_max_conns [emb_limit] [norandomseq]]] [udp udp_max_conns]
• Maximum number of simultaneous UDP connections that the local IP hosts are allowed.
- A value of 0 disables protection (default).
- Idle connections are closed after the time specified in the udp timeout command.
fw1(config)# nat (inside) 1 0.0.0.0 0.0.0.0 200 25 fw1(config)# static (inside,outside) 192.168.0.11 172.16.0.2 0 0 udp 100
© 2005 Cisco Systems, Inc. All rights reserveO.SNPA v4.0—4-39
Use udpmaxconns to set the maximum number of simultaneous UDP connections that the internal network IP hosts are each allowed to use. Idle connections are closed after the time that is specified by the timeout udp command. The default is 2 minutes.
Use tcp max conns to set the maximum number of simultaneous TCP connections that the internal network IP hosts are each allowed to use. Idle connections are closed after the time that is specified by the timeout conn command. The default is 1 hour. In the NAT example in the figure, the maximum number of TCP connections is set to 200 and the embryonic limit is set to 25.
In both the nat and static commands, you can set the maximum number of simultaneous UDP connections even when the maximum number of simultaneous TCP connections is not set, by using the keyword udp. This allows the two limits to be exclusively configured. In the example in the figure, the static connection between 192.168.0.11 and 172.16.0.2 is limited to a maximum of 100 UDP connections.
The administrator can also set the TCP, UDP, and embryonic limits on a per-flow basis by using the set connection command in a policy map.
Continue reading here: Show conn detail Command
Was this article helpful?