Re: [fw-wiz] Fragmentation over VPN



On both interfaces reduce the size to say about 1350 max to take into
account the ipsec overhead. Otherwise larger packets will be dropped since
when they go to the interface ipsec (esp) overhead will put the packet over
the 1500 allowed across most router interfaces in route:

ie do this:
ip tcp adjust-mss 1350



On 3/8/07, Alex <anobre1@xxxxxxxxx> wrote:

Hi everyone,

First time poster here (as if anyone cared <g>).

I have this scenario:

Three offices need to connect via IPSec (L2L) and each also runs EZVPN
server for clients to connect to.

There is a 506E, and ASA5510 and an ISR 1801W. The configuration for the
506E and ASA5510 were easy enough and everything is working fine. On the
1801 is a different story. I get the SA's done with no problems, but then
no
other traffic flows through and I suspect this has to do with
fragmentation.

On the outside interface (Dialer1), I have "mtu 1492" and on the inside
(VLAN1) I have "ip tcp adjust-mss 1452". Everyone behind the device can
browse the internet without any problems (yes, PAT).

Can some kind soul please provide some ideas on how to get around it?

Much appreciated.

Alex.

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: IPMP enabled serious Network Problems
    ... inet 10.xx.xx.49 netmask ffffff00 broadcast xxxxxxx.255 ... Turn off this option to track all network interfaces ... input packets with dribble condition detected ...
    (comp.unix.solaris)
  • Re: [PATCH 4/5] ieee802154: add documentation about our stack
    ... +Currently only IEEE 802.15.4 layer is implemented. ... +Most of IEEE 802.15.4 MLME interfaces are directly mapped on netlink commands. ... +2) 'SoftMAC' or just radio. ... are you sending IP packets over this ARPHRD_IEEE802154 network devices ...
    (Linux-Kernel)
  • Re: ISR CBAC prolem
    ... When I apply CBAC onto inside interface without any ACL's ... Have you determined if packets are arriving out of order? ... I'm running CEF and netflow on both outside and inside interfaces... ... > increase the inspection timouts. ...
    (comp.dcom.sys.cisco)
  • Re: Help Broadcasting a UDP packet on the LAN:URGENT
    ... We use all-ones packets well ... > network interfacethey should be using to do this. ... > interfaces because you have a per-network broadcast address if you want ... That way you get "for free" to control which interfaces should send ...
    (freebsd-net)
  • Bridging interfaces
    ... I seem to be having some trouble bridging interfaces in FreeBSD 6.2-STABLE. ... packets transmitted, 2 packets received, 0% packet loss ... inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255 ...
    (freebsd-questions)