<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Differences btn sysopt connection tcp-mss / tcp-map exceed-mss allow in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737706#M1001099</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a bit confused, we are looking into troubleshooting some issues with MSS and I came across 2 parameters which I am not sure if they both serve the same purpose....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) sysopt connection tcpmss 1380&lt;/P&gt;&lt;P&gt;According to cisco description, this sets the maximum mss to value of 1380. Does this implies that in a connection from one interface leg of the firewall to another, the MSS value btn two hosts will never "negotiate" above 1380? [in a sense Firewall, intercepts messages and changes TCP MSS value to 1380 during the TCP Handshake?]. Or is this feature only complementary to IPSEC and VPN issues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) tcp-excced warning. TCP Exeed warmning occurs if btn a handshake the receiver or the sender transmit data with a value higher or lower than the value mutually agreed during TCP Handshake. Has though this "mutually" agreed value have to do anything with the value of the sysopt? or it "stands" by itself? &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:54:58 GMT</pubDate>
    <dc:creator>pavlosd</dc:creator>
    <dc:date>2019-03-11T10:54:58Z</dc:date>
    <item>
      <title>Differences btn sysopt connection tcp-mss / tcp-map exceed-mss allow in ASA</title>
      <link>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737706#M1001099</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a bit confused, we are looking into troubleshooting some issues with MSS and I came across 2 parameters which I am not sure if they both serve the same purpose....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) sysopt connection tcpmss 1380&lt;/P&gt;&lt;P&gt;According to cisco description, this sets the maximum mss to value of 1380. Does this implies that in a connection from one interface leg of the firewall to another, the MSS value btn two hosts will never "negotiate" above 1380? [in a sense Firewall, intercepts messages and changes TCP MSS value to 1380 during the TCP Handshake?]. Or is this feature only complementary to IPSEC and VPN issues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) tcp-excced warning. TCP Exeed warmning occurs if btn a handshake the receiver or the sender transmit data with a value higher or lower than the value mutually agreed during TCP Handshake. Has though this "mutually" agreed value have to do anything with the value of the sysopt? or it "stands" by itself? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737706#M1001099</guid>
      <dc:creator>pavlosd</dc:creator>
      <dc:date>2019-03-11T10:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Differences btn sysopt connection tcp-mss / tcp-map exceed-m</title>
      <link>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737707#M1001101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the sysopt connection tcpmss value is only for IPsec and VPN. The tcp-exceed warning has nothing to do with the sysopt connection tcpmss value.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2007 17:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737707#M1001101</guid>
      <dc:creator>wong34539</dc:creator>
      <dc:date>2007-08-14T17:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Differences btn sysopt connection tcp-mss / tcp-map exceed-m</title>
      <link>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737708#M1001104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sysopt connection tcpmss value is related to all tcp connection through the pix/asa. Even if they are tunneled through VPN or if they go from local to local LAN PIX/ASA interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tcp-exceed, is there to verify that the mss value agreed btn two peers is not violated. So the maximum tcp-exceed value the PIX/ASA will allow is the value of "sysopt connection tcpmss value" + 20 (TCP HDR) + 20 (IP HDR).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone is not using any VPN tunneling then it is safe to change the value of tcpmss to 1460 (+20 +20 = 1500).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Sep 2007 13:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/differences-btn-sysopt-connection-tcp-mss-tcp-map-exceed-mss/m-p/737708#M1001104</guid>
      <dc:creator>pavlosd</dc:creator>
      <dc:date>2007-09-01T13:49:45Z</dc:date>
    </item>
  </channel>
</rss>

