In article , Ilan wrote: :Is PIX6 to PIX7 a firmware upgrade?
No, it's a software update. PIX 7.0(1) is available for the PIX 515/515E, 525, and 535 only.
:May I understand from your answer that PIX7 would support an idle session?
No, you should understand from my answer that PIX 7.0(1) is new (April 2, 2005), that there are a large number of changes in it, that I have not had a chance to test it myself, and I have not had a chance to study the documentation in detail. Under the circumstances, it would be wrong for me to rule out the possibility that PIX 7.0(1) allows per-session or per-ACL idle times.
I do not -remember- seeing anything like that in the release notes, but I was not looking for it and I might have overlooked it -- and the release notes sometimes overlook new capabilities that are described in the Command Reference. There might be some new capability introduced. I don't think it is -likely- but to say Yes or No with certainty would require someone more familiar with the PIX 7.0(1) documentation.
As I indicated in an earlier answer, if you do not want idle TCP sessions to time out, you can set the idle timeout to 0:00:00, but that will affect *all* sessions. It would effectively crash our PIX within a few days if we did it at our site, as we use a program that I have no realistic hope of banning but which never cleans up after itself.