<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Ace 4710 - Strange tcp mss problem in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300937#M40653</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is reproducible then i would suggest opening a case with TAC to investigate further. 536 is minimum value and ACE ideally should not stop forwarding it it is getting response from server and client. How do you know it was ACE which stopped passing traffic? Do we have a pcap showing that server replied with packet which ACE received and didn't forward to the client and vice-versa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have all this information and show tech during the issue i would suggest opening a case with TAC for further investigation into the matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 20 Oct 2013 13:33:53 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2013-10-20T13:33:53Z</dc:date>
    <item>
      <title>Cisco Ace 4710 - Strange tcp mss problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300936#M40652</link>
      <description>&lt;P&gt;I am seeing a strange behaviour in a ACE 4710 (A5(2.1)).&lt;/P&gt;&lt;P&gt;I have ssl proxy configured and it mostly works. The only problem is in one provider that&amp;nbsp; is changing the mss to 536, for this https connection the ACE begins sending data and then just stops. Nothing appears at the ACE logs...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After some tests, a workaround has been found, if i configure a minimum mss with: &lt;STRONG style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;"&gt;set tcp mss min 600&lt;/STRONG&gt;&lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;"&gt; &lt;/EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;max 1380 then it works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone had this type of behaviour? Is there another better fix/workaround?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2013 09:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300936#M40652</guid>
      <dc:creator>vladimirsaltao</dc:creator>
      <dc:date>2013-09-04T09:08:07Z</dc:date>
    </item>
    <item>
      <title>Cisco Ace 4710 - Strange tcp mss problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300937#M40653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is reproducible then i would suggest opening a case with TAC to investigate further. 536 is minimum value and ACE ideally should not stop forwarding it it is getting response from server and client. How do you know it was ACE which stopped passing traffic? Do we have a pcap showing that server replied with packet which ACE received and didn't forward to the client and vice-versa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have all this information and show tech during the issue i would suggest opening a case with TAC for further investigation into the matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Oct 2013 13:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300937#M40653</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-10-20T13:33:53Z</dc:date>
    </item>
    <item>
      <title>I have the same problem. The</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300938#M40654</link>
      <description>&lt;P&gt;I have the same problem. The problem only occurs when incoming HTTPS is converted to HTTP on the ACE using NAT configuration. In one scenario the browser (10.170.44.71) send no MSS option when the connexion with the ACE (&lt;SPAN style="font-size:12px;"&gt;10.170.72.23&lt;/SPAN&gt;) is initiated as in A) so default value of 536 is assumed&lt;/P&gt;&lt;P&gt;A) Trace from Client establishing a HTTPS connection&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;297&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.750800000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.44.71&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.72.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 61266→443 [SYN] Seq=0 Win=8192 Len=0 WS=4 SACK_PERM=1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;298&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.751020000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.72.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.44.71&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 443→61266 [SYN, ACK] Seq=0 Ack=1 Win=32768 Len=0 MSS=1460&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the backend in HTTP, the ACE established a connection with a MSS of only 503, which is lower than the minimum TCP/IP value of 536.&lt;/P&gt;&lt;P&gt;B) Trace From IIS server&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;26863&amp;nbsp;&amp;nbsp;&amp;nbsp; 41.563459000&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.132.211&amp;nbsp; 10.170.73.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80→11649 [SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=1460&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;26862&amp;nbsp;&amp;nbsp;&amp;nbsp; 41.563362000&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.73.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.132.211&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11649→80 [SYN] Seq=0 Win=32768 Len=0 MSS=&lt;STRONG&gt;503&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;(see attached image for complete capture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when the IIS HTTP server replies, the packet gets dropped by the ACE, the client never receives it. I also notice the no fragmentation flag being set by IIS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In traces C) and D) we tried with a HTTPS browser that is sending a MSS of 1427, this works, the answer from the HTTP server get back from the ACE&lt;/P&gt;&lt;P&gt;C) Trace from Client HTTPS Browser&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.90.47&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.72.23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53956→443 [SYN] Seq=0 Win=8192 Len=0 MSS=&lt;STRONG&gt;1460 &lt;/STRONG&gt;WS=256 SACK_PERM=1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;D) Trace from&amp;nbsp; IIS Web Server&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;5798&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.019072000&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.73.27&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.132.36&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8096→80 [SYN] Seq=0 Win=32768 Len=0 MSS=1427&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;5799&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.019196000&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.132.36&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.170.73.27&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80→8096 [SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=1460&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What seems to be a bug is that the MSS of the HTTP connexion established by the ACE with IIS server seems to compute its MSS by substracting 33 from the MSS received by the HTTPS incoming connexion.&lt;/P&gt;&lt;P&gt;No MSS scenario: 536 – 33 = 503&lt;/P&gt;&lt;P&gt;Large MSS scenario: 1460 – 33 = 1427&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would expect the MSS to be always higher than 536 given the minimum MTU of a IP Network being 576. Why is 33 bytes always substracted the client MSS to set the MSS from outgoing connexions ?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 15:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-4710-strange-tcp-mss-problem/m-p/2300938#M40654</guid>
      <dc:creator>pierre.morency</dc:creator>
      <dc:date>2015-02-18T15:54:10Z</dc:date>
    </item>
  </channel>
</rss>

