Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

PIX v7 - fragmentation & MTU's

Posted on 2006-06-12
5
Medium Priority
?
1,228 Views
Last Modified: 2013-11-16
Hi all,

I have a situation where I have upgraded one of our PIX to 7.0.4 (from 6.3.5) and a few things have broken. The layout of the PIX looks like this:

home PIX --VPN-- support PIX ---LAN--- main PIX ---VPN--- store PIX

So there are FOUR PIX firewalls in use:

home PIX - PIX 501 v6.3.5, used to allow the support personel remote access to the corporate LAN and the store PC's.
support PIX - PIX 501 v6.3.5, used to get around the earlier issue with PIX that traffic coming in one VPN tunnel couldn't be routed back out of the same interface to another tunnel.
main PIX - PIX 515E v7.0.4, all of the stores (140 of them) have a VPN tunnel to this PIX.
store PIX - PIC 501 v6.3.1-6.3.5 (varies)

So for a support person to get remote access to a store PC the packets travels across VPN to the main office via an IPSec tunnel between home PIX & support PIX, across the LAN between support PIX & main PIX and then across IPSec tunnel between main PIX and store PIX before finally getting to store PC.

(hope this all makes sense)

The problem I have is that after upgrading the main PIX to 7.0.4 certain things don't work for the support people at home. The most notable being windows file browsing/transfer and PcAnywhere connections lockup after only a few seconds (they connect most of the time). Prior to the upgrade on the main PIX everything was working flawlessly for over 2 years now.

From past experience the problems I am seeing sometimes point to MTU/fragmentation issues.

My question is what does the 7.0.4 code do (or not do) that the 6.3.5 does ?

From the "sho run all" output (7.0.4), the following lines look interesting:

crypto ipsec fragmentation before-encryption outside
crypto ipsec fragmentation before-encryption inside
crypto ipsec df-bit copy-df outside
crypto ipsec df-bit copy-df inside

I've looked in the command reference, but the description is very basic in that it is simply a description and doesn't really explain to much what the commands DO.

Can anyone make any suggestions on what the problem might be. Rverting back to 6.3.5 is NOT an option.

I have logged a case with TAC, but is it just me or does anyone else find them increasingly less useful in that they don't seem to have good product knowledge anymore. Especially with the v7 OS. The problem is clearly related to something that has changed in the upgrade, so I would expect they might be focussing on what has changed, but most of the support people don't really seem to have any knowledge of the v7 OS and it's changes. I'm turning to EE in the hope that I might get a quicker resoution here. Thanks.
0
Comment
Question by:td_miles
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 13

Author Comment

by:td_miles
ID: 16891997
finally TAC pulls their finger out, looks like the command I am requiring is:

sysopt connection tcpmss 1300

will be requesting refund on this question.
0
 
LVL 11

Expert Comment

by:prueconsulting
ID: 16897588
1300 seems very small for the tunnels.
How are they connected ?
0
 
LVL 13

Author Comment

by:td_miles
ID: 16898038
well, according to Cisco in the command reference:

1380 data + 20 TCP + 20 IP + 24 AH + 24 ESP_CIPHER + 12 ESP_AUTH + 20 IP = 1500 bytes

So 1380 is the deafult that it is set to. I was having issues so 1300 is a nice round number to set it to. 1300 is also the number that the Cisco VPN client sets the MTU to when you install it on a PC.
0
 
LVL 5

Accepted Solution

by:
Netminder earned 0 total points
ID: 16932477
Closed, 500 points refunded.
Netminder
Site Admin
0

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question