<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IP MTU issues across GRE/IPSEC Tunnels in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057863#M1001912</link>
    <description>&lt;P&gt;Any links/insight into IP MTU issues in an MS environment with Cisco Routing IOS VPN GRE/IPSEC Tunnels&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:00:09 GMT</pubDate>
    <dc:creator>bob.forster</dc:creator>
    <dc:date>2020-02-21T11:00:09Z</dc:date>
    <item>
      <title>IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057863#M1001912</link>
      <description>&lt;P&gt;Any links/insight into IP MTU issues in an MS environment with Cisco Routing IOS VPN GRE/IPSEC Tunnels&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057863#M1001912</guid>
      <dc:creator>bob.forster</dc:creator>
      <dc:date>2020-02-21T11:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057864#M1001913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are some MTU and TCP MSS issues associated with GRE tunnels. Generally it is associated with web browsing and file shares. Here are a few guides to help you out for your install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk827/tk369/technologies_tech_note09186a0080093f1f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk827/tk369/technologies_tech_note09186a0080093f1f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Sep 2008 21:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057864#M1001913</guid>
      <dc:creator>Mark Yeates</dc:creator>
      <dc:date>2008-09-10T21:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057865#M1001914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;adjust your tunnel interface mtu size to 1420 and issue the command ip tcp adjust-mss 1380. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2008 16:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057865#M1001914</guid>
      <dc:creator>leej</dc:creator>
      <dc:date>2008-09-12T16:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057866#M1001915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, that's what I typically do IP MTU 1420 on the outside interface (which forces all VPN Tunnels to 1396) and then IP TCP MSS 1270.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Works for over 100 tunnels I have with other clients, but this client still sees some Group Policy issues. &lt;/P&gt;&lt;P&gt;We are looking at doing IP MTU right on the client Registry Keys and this seems to clear up ALL issues (With Routers set to NO IP MTU on Outside physical interface, IP MTU 1400 on Tunnels and TCP MSS 1270 on Inside interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Sep 2008 20:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057866#M1001915</guid>
      <dc:creator>bob.forster</dc:creator>
      <dc:date>2008-09-12T20:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057867#M1001916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we've had a problem with w2k3 servers and GRE tunnels, where the servers would start to ignore the ICMP packet too big messages from the routers after a little while, causing TCP sessions to fail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;info on the bug is here: &lt;A class="jive-link-custom" href="http://support.microsoft.com/kb/898060/" target="_blank"&gt;http://support.microsoft.com/kb/898060/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;setting the mtu in the registry to an approipiate value, or installing the patch / service pack in the link will fix that issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Sep 2008 22:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057867#M1001916</guid>
      <dc:creator>jonesandrew</dc:creator>
      <dc:date>2008-09-14T22:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: IP MTU issues across GRE/IPSEC Tunnels</title>
      <link>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057868#M1001917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We had issues with the MTU of the GRE tunnel with users accessing an Exchange server.  We had to bump the MTU of the tunnel up to 1600 to account for the MTU plus the 24-byte GRE overhead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this link on CCO:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk827/tk369/technologies_tech_note09186a0080093f1f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk827/tk369/technologies_tech_note09186a0080093f1f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is more detailed info at:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2008 13:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-mtu-issues-across-gre-ipsec-tunnels/m-p/1057868#M1001917</guid>
      <dc:creator>rmalloy</dc:creator>
      <dc:date>2008-09-25T13:11:00Z</dc:date>
    </item>
  </channel>
</rss>

