Re: [fw-wiz] VPN Issue with Certs and fragmentation



Robby,

Thanks for the reply. We're using the Cisco software and using Cisco
5520ASAs to terminate the VPN. I've tried configuring the vpn profile to
use TCP over port 10000 and that too fails. I'm going to try lowering
the MTU on the public interface of an ASA to see if that helps.

Thanks,

simon

________________________________

From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxxxx
[mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxxxx] On Behalf Of
Robby Cauwerts
Sent: Wednesday, September 12, 2007 3:06 AM
To: Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] VPN Issue with Certs and fragmentation


On 9/11/07, Bell Simon (RBNA/CIT1.12) <Simon.Bell@xxxxxxxxxxxx> wrote:

We occasionally have customers call in reporting that they're
never
prompted for credentials when attempting to connect to the VPN.
This
happens most often when they're at a hotel/public hotspot.
However, if
they use a profile based on a preshared key instead of a cert
authentication, they connection works w/o issue. I've captured
traffic
off a failed user and it looks like during a cert auth IPSec
tunnel
there's a fair amount of packet fragmentation.




The fragmentation can be solved by using IKE over tcp.
What type of vpn (vendor) are you using?

Br.
Robby




_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: HELP: NFS mount hangs when attempting to copy file
    ... A lot of these VPN solutions are unfriendly to MTU ... Sun uses TCP by default when mounting NFS ... that's breaking the PMTU discovery if you can (usually it's too ...
    (Linux-Kernel)
  • Re: New VPN Setup
    ... TCP port 47. ... GRE is at the same level as TCP not over. ... Q2:You can TSE one of you DC and add the user with the local ... > I am trying to setup a VPN for a small company of 10. ...
    (microsoft.public.win2000.ras_routing)
  • Re: VPN Error 720
    ... I think the Zywall is not configured for VPN passthrough. ... TCP Port 1723 on the other endpoint. ... In the system log on the server I get the following message: ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA VPN Accessing Mapped Drives
    ... Exactly how are these applied to the ISA policies you created for the VPN ... 139 TCP ... 53 UDP ...
    (microsoft.public.isa.vpn)
  • Re: Samba over SSH
    ... try using nfs with tcp connection through ... even in the case of a disconnection of the vpn. ... We use this to connect to a cvs server and it works great. ... >> ssh. ...
    (freebsd-questions)