Solved

Need help configuring my Cisco ASA Firewall to extend MSS limit for outbound traffic

Posted on 2007-11-13
3
2,157 Views
Last Modified: 2008-10-20
I have a Cisco ASA 5510 firewall and my company uses a third party POP3 providor for email.
I have just installed a Konica Multi-purpose copier that can scan a document and email it. However, when I do this, my firewall stops it with the message:
Dropping TCP packet from inside:10.203.15.202/1025 to outside:204.107.103.101/25, reason: MSS exceeded, MSS 1380, data 1460

I have seen how I can configure MSS to exceed for traffic coming in, but how can I configure it for traffic going out
0
Comment
Question by:eleeexpertsexchange
3 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 250 total points
ID: 20276536
Try these statements:

access-list mss_allow_list extended permit tcp any host 204.107.103.101
tcp-map tcp-mss-map
  exceed-mss allow
class-map mss-map
 match access-list mss_allow_list
policy-map mss-map
 class mss-map
  set connection advanced-options tcp-mss-map
service-policy mss-map interface outside
0
 

Author Comment

by:eleeexpertsexchange
ID: 20276812
This works. Thanks very much

0
 
LVL 1

Expert Comment

by:Eirejp
ID: 34236429
No luck I am afraid.

I applied the configuration without error but one command did not show up in the show run as if it was already the default.
"exceed-mss allow"

So it looks like it applied a empty policy to the external interface. I tried a couple of times but the tcp-map tcp-mss-map comes up blank.

I am still see these sorts of errors in the logs.



6	Nov 30 2010	14:37:09						PMTU-D packet 1420 bytes greater than effective mtu 1050, dest_addr=[WAN IP], src_addr=[Random web site], prot=tcp

Open in new window

0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question