Here is a sample of some of the timeout commands from a Cisco ASA firewall:
timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute
timeout xlate 0:05:00 timeout conn 0:50:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225
1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute
Almost the same layout for PIX or ASA, accounting for differences in platform and image version. To go beyond this default set of commands for a connection timeout, a class map can be configured for a certian type of network traffic. For example, an access-list can be entered into the class map permitting any any traffic destined for TCP port 22. That class map can then be used to configure a specific timeout for that traffic class.
access-list SSHtraffic extended permit any any eq 22 class-map SSHconnections description Any SSH network traffic match access-list SSHtraffic policy-map SSHtimeout class SSHconnections set connection timeout tcp 00:05:00 reset service policy SSHtimeout interface outside