Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Re: Help with FW Config on C871

Reply
Thread Tools

Re: Help with FW Config on C871

 
 
Trendkill
Guest
Posts: n/a
 
      02-09-2009
Line breaks would be helpful.
 
Reply With Quote
 
 
 
 
bod43
Guest
Posts: n/a
 
      02-09-2009
On 9 Feb, 12:28, Trendkill <jpma...@gmail.com> wrote:
> Line breaks would be helpful.


While I wouldn't disagree, this reminds me of something I have
seen a few times.

I have noticed that the hotmail login request - the data sent
when you press "login" or whatever it is called, does not fit
in a single packet and results in one full size segment and
a second smaller segment (this was years ago and may
have changed).

If path MTU discovery is not working then the first packet
can get dropped by your router.

Without fully analysing the config I wonder if
changing

interface BVI1
ip tcp adjust-mss 1452
to something significantly smaller
just might magically fix it.

I notice that your VLAN 1 adjust-mss is 1412. That seems OK
unless you are using ipsec in which case I use 1300.

I see no point is trying to trim it to the last byte.

1452 seems reasonable (1460 - (1500 - 1492)
but with many TCP options enabled I suppose
you might be running out of that.

Maybe enabling the firewall is breaking Path MTU
discovery?

If required please state the exact commands for
"disabling/enabling" the firewall.
 
Reply With Quote
 
 
 
 
Andreas Heinzelmann
Guest
Posts: n/a
 
      02-10-2009
>> Line breaks would be helpful.
sorry for the missing Line breaks!

I managed to get the Live-Messenger working. It was the deep inspections of
the IOS FW.
I disabled deep inspection and voila no more problems.

Thanks for your efforts.

Andy


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Question on VPN Termination on C871 Andy Doe Cisco 1 04-02-2009 09:59 AM
C871 Access from WAN-Side (internet)? Andreas Heinzelmann Cisco 2 11-06-2007 08:44 AM
C871 Remote access Andreas Heinzelmann Cisco 0 11-05-2007 08:51 PM
C871 Remote access Andreas Heinzelmann Cisco 0 11-05-2007 08:49 PM
C871 Remote access Andreas Heinzelmann Cisco 9 11-05-2007 08:45 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57