Advertisement

04.06.2007 at 06:07AM PDT, ID: 22496206
[x]
Attachment Details

MTU Packet size, VPN with Active Directory

Asked by AccessYourBiz_Com in Virtual Private Networking (VPN), Miscellaneous Networking, Active Directory

Tags: , , ,

I have a windows 2003 network, with a mix of 2003 and 2000 domain controllers, there are branch offices connected to the lan via a VPN, recently this vpn was upgraded from Pick boxes to Cisco 1720, since then, active directory relication has been troublesome at best. I tested the max packet size with ping, 1472 gets fragmented, 1380 is the max size which can go through without fragmentation.

The currect packet size is the default of 1472. There are about 15 DCs in the domain, I spoke to the Router Vendor, who reports that he can not increase the packet size because of the tunnel and the ecription he is using.

Just a few questions:

1)  If I make no changes, what is the actions AD will take, will it try the 1472, then scale down to the largest non fragmented packet size, or will it fragment the packet and what would the effect of this be.

2) Do I need to edit the registry on each DC to the 1380 packet size.

3) Are there any tools which can help determine if the AD replication packets are being fragmented as currently configures, I know I can use ping to determin the max no fragmented size, but can a see what AD is doing.

4) what would be the recommended solution to what is going on here.

Thanks
Steve
Start Free Trial
[+][-]04.06.2007 at 08:36AM PDT, ID: 18864624

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]04.06.2007 at 08:54AM PDT, ID: 18864766

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.06.2007 at 09:30AM PDT, ID: 18864997

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.06.2007 at 09:36AM PDT, ID: 18865044

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.10.2007 at 11:38AM PDT, ID: 18884471

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.10.2007 at 11:47AM PDT, ID: 18884529

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Virtual Private Networking (VPN), Miscellaneous Networking, Active Directory
Tags: mtu, size, vpn, packet
Sign Up Now!
Solution Provided By: RobWill
Participating Experts: 3
Solution Grade: B
 
 
[+][-]04.10.2007 at 04:27PM PDT, ID: 18886215

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.12.2007 at 01:47AM PDT, ID: 18896424

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]04.24.2007 at 03:28PM PDT, ID: 18970100

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32