Advertisement

07.27.2007 at 06:12AM PDT, ID: 22725271 | Points: 500
[x]
Attachment Details

Netscreen ipsec vpn ssl / mtu connection issue

Asked by demonzzz in IPSec Security Protocol, Virtual Private Networking (VPN), Networking Hardware Firewalls

Tags: , , ,

We have a ipsec vpn tunnel set up between a netscreen ns5gt in our office and a netscreen 204 in our datacenter.

The vpn works fine except for when we try to access ssl-enabled applications running on servers in the datacenter, when the connections time out. The office subnet is routed via the tunnel, so no nat is involved.


I think this is mtu-related somewhere because I can open tcp sockets to the ssl application (telnetting to that port) and see ssl error messages in the applications log when I do this, but accessing it properly via a browser results in nothing in the log at all.

After doing some testing, I have found that the max icmp packet I can send over the tunnel is 1418 bytes, so somewhere something is limiting mtu to 1446 bytes (1418 icmp + 28 byte overhead).

If I route to the same IP either via the public network without the tunnel, or via our other adsl connection, I can send icmp packets of 1472 bytes, which is what I would expect when the MTUs are all 1500.


Ive tried setting flow tcp-mss to various values to reduce the packet size but this has not made any difference.

Any suggestions are most welcome!
Start Free Trial
[+][-]07.27.2007 at 05:58PM PDT, ID: 19583228

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.28.2007 at 07:18AM PDT, ID: 19584750

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.28.2007 at 08:41PM PDT, ID: 19586941

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.28.2007 at 08:59PM PDT, ID: 19586970

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.30.2007 at 03:36AM PDT, ID: 19591358

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.30.2007 at 04:24AM PDT, ID: 19591545

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.30.2007 at 07:00AM PDT, ID: 19592455

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.30.2007 at 04:55PM PDT, ID: 19596786

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.30.2007 at 07:03PM PDT, ID: 19597302

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.06.2007 at 01:34AM PDT, ID: 19636954

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.28.2008 at 07:55AM PDT, ID: 22335611

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32