Location internet browsing after Cisco ASA install

Posted on 2014-08-06
Last Modified: 2014-10-21
We have a very odd situation that I hope I can explain fully.

We are in the process of setting up an office in Japan with site to site VPN to our main office in London. Their previous setup was provided by their ISP which consisted of a Yamaha router and a Buffalo 24 port switch.
We have just replaced both units with a Cisco Catalyst 2960-X switch and a Cisco ASA 5505 firewall. L2L tunnel has been configured, established and test with the network in london so that the Japan office obtains DNS settings from London server (DHCP is configured from the ASA)
This all works fine, albeit a little slower than expected, apart from the fact that we are no unable to browse several websites. The first one I found was and another prime example is Twitter, other websites seem to be fine. Just the sites that are possibly location detecting. Due to the DNS setup, the outside world consider the Japan office to reside in the UK!
Since then we have disabled to L2L tunnel to see if it was that, but the problem still exists. I have no further ideas and have suggest we roll back the hardwae change until it can be resolved.
I have read that it could be ISP related and that international badwidth maybe handled poorly or very saturated.
Another idea that it might be an MTU or MSS issue on the PPPoE side of he ASA appliance but I have little knowledge on this.
I know this description may sound rather vague but it's an opener and very open to ideas and suggestions.
Question by:Nick Smith
    LVL 14

    Expert Comment

    if you suspect a DNS issue, you can do a nslookup of the offended websites and try to reach them from browser by IP address instead of URL.
    That said, if you have no websense or other web filtering in place, i do not think ASA is to blame.
    hope this helps

    Author Comment

    by:Nick Smith
    Yes, I did try that but I still can't hit the websites.
    We took down the VPN tunnel so the DNS resolved to the ISP rather than the London network but didn't make any difference.
    I'm waiting to get the router back to roll back the hardware changes to its original state (so no Cisco kit) and see if it resolves. If this is the case then it must be the ASA!
    Strangely enough, their internet package allows of speeds up to 200mbps (but average around 100mbps) but at the moment I am only getting a max of 15mbps.

    Accepted Solution

    Would anybody know if there is an official fault with PPPoE connections with ASA appliances?

    I think this could be the problem, as I have put in the old Yamaha router and everything is working as normal (apart from site to site VPN of course)

    Author Closing Comment

    by:Nick Smith
    resolved myself

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    VM backup deduplication is a method of reducing the amount of storage space needed to save VM backups. In most organizations, VMs contain many duplicate copies of data, such as VMs deployed from the same template, VMs with the same OS, or VMs that h…
    Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
    This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
    To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now