Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Split Tunnel Blocks http through tunnel but passes http around tunnel

Reply
Thread Tools

Split Tunnel Blocks http through tunnel but passes http around tunnel

 
 
a.nonny mouse
Guest
Posts: n/a
 
      09-16-2004
I've created a tunnel between two offices using a 501 and 506e. All
functions of the firewall work normally. I can get on the Internet, pass
E-mail, telnet, ftp etc. However I cannot get to a private Extranet behind
the 506e. I can ping, ftp and e-mail but http traffic does not get through.
In the web browser I get "Web site found, waiting on host" in the status bar
but nothing else.

Any thoughts on where to start looking?


 
Reply With Quote
 
 
 
 
Scooby
Guest
Posts: n/a
 
      09-16-2004
"a.nonny mouse" <(E-Mail Removed)> wrote in message
news:C2j2d.165812$%(E-Mail Removed) ...
> I've created a tunnel between two offices using a 501 and 506e. All
> functions of the firewall work normally. I can get on the Internet, pass
> E-mail, telnet, ftp etc. However I cannot get to a private Extranet

behind
> the 506e. I can ping, ftp and e-mail but http traffic does not get

through.
> In the web browser I get "Web site found, waiting on host" in the status

bar
> but nothing else.
>
> Any thoughts on where to start looking?
>
>


How are you defining what goes through the tunnel. Have you set a list of
'interesting traffic'? What does that look like?


 
Reply With Quote
 
 
 
 
Rob
Guest
Posts: n/a
 
      09-19-2004
"a.nonny mouse" <(E-Mail Removed)> wrote in message news:<C2j2d.165812$%(E-Mail Removed) t>...
> I've created a tunnel between two offices using a 501 and 506e. All
> functions of the firewall work normally. I can get on the Internet, pass
> E-mail, telnet, ftp etc. However I cannot get to a private Extranet behind
> the 506e. I can ping, ftp and e-mail but http traffic does not get through.
> In the web browser I get "Web site found, waiting on host" in the status bar
> but nothing else.
>
> Any thoughts on where to start looking?


Make sure as said that your acls are checking the correct traffic then
try reducing the tcp packet size on your ethernet interfaces on both
sides.
try first with "ip tcp adjust-mss 1380".
The max i think is 1480 but you will find a level that will work in
your setup.
Let me know!
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX VPN Client connects but not traffic passes through rambur Cisco 5 04-25-2007 03:52 AM
PIX lan-to-lan IPSEC comes up...no traffic passes tunnel Arjan Cisco 0 11-02-2005 11:28 PM
Cisco VPN Client connects but no traffic passes through. Mephesto Cisco 0 06-24-2005 04:24 PM
procs/blocks - blocks with procs, blocks with blocks? matt Ruby 1 08-06-2004 01:33 AM



Advertisments