<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to find the highest possible MTU in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46347#M1063006</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to find out, wich is the highest possible MTU. So I send a PING -L XXXX -F to the Pix outside, from outside. XXXX is standing for the bytes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 992 (and lower) -F&lt;/P&gt;&lt;P&gt;I got a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 993 (up to1472) -F&lt;/P&gt;&lt;P&gt;the ping timed out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 1473 (and higher) -F&lt;/P&gt;&lt;P&gt;Fragmentation is needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand, why it timed out between 993 an 1472.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i try the same to a router (same internet connection), the ping works up to 1472, with no time out. Upeer 1472 I get the fragmentation message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have enyone an answer?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:02:28 GMT</pubDate>
    <dc:creator>thomas.schmitz</dc:creator>
    <dc:date>2020-02-21T06:02:28Z</dc:date>
    <item>
      <title>Trying to find the highest possible MTU</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46347#M1063006</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to find out, wich is the highest possible MTU. So I send a PING -L XXXX -F to the Pix outside, from outside. XXXX is standing for the bytes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 992 (and lower) -F&lt;/P&gt;&lt;P&gt;I got a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 993 (up to1472) -F&lt;/P&gt;&lt;P&gt;the ping timed out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING xxx.xxx.xxx.xxx -L 1473 (and higher) -F&lt;/P&gt;&lt;P&gt;Fragmentation is needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand, why it timed out between 993 an 1472.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i try the same to a router (same internet connection), the ping works up to 1472, with no time out. Upeer 1472 I get the fragmentation message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have enyone an answer?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46347#M1063006</guid>
      <dc:creator>thomas.schmitz</dc:creator>
      <dc:date>2020-02-21T06:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to find the highest possible MTU</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46348#M1063008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might consider pre-fragmentation before the packet enters the tunnel.  See &lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121newft/121limit/121e/121e11/lokahead.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121newft/121limit/121e/121e11/lokahead.htm&lt;/A&gt; for details.  I hope this helps.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2002 19:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46348#M1063008</guid>
      <dc:creator>ssoberlik</dc:creator>
      <dc:date>2002-05-02T19:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to find the highest possible MTU</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46349#M1063010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My problem occurs also without any encryption. I'm connected to the internet and send a ping to the outside interface of the PIX. First a thought it is a problem with the router from the ISP, but we have also a CISCO 1605 connected to the same ISP router and there the ping work realy fine until 1472 bytes the I get the message fragmentition needed.&lt;/P&gt;&lt;P&gt;If I'm connected via the VPN Client 3.51 and send a ping to inside, I get the same results, but additional on the PIX, if debug ipsec is on, a message like this: IPSEC(ipsec_cipher_handler): ERR: bad pkt 10.1.80.3-&amp;gt;10.1.1.1&lt;/P&gt;&lt;P&gt;I searched in the errordecoder from Cisco, but there are no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, the pre-fragmentation is by default on and I didn't switch it off. It occurs not in IPSEC transfermode, which I'm using.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2002 08:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46349#M1063010</guid>
      <dc:creator>thomas.schmitz</dc:creator>
      <dc:date>2002-05-03T08:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to find the highest possible MTU</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46350#M1063012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same problem that you described in this post. In my case it is between two PIX that have a site-to-site VNP between them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And also, I my case the PING timed out at 993.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a work-around?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2004 00:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46350#M1063012</guid>
      <dc:creator>fbenny</dc:creator>
      <dc:date>2004-08-05T00:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to find the highest possible MTU</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46351#M1063013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'am investiguated on the same issue. Did you get an answer? Do you have a workaround?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frédéric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2005 10:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-find-the-highest-possible-mtu/m-p/46351#M1063013</guid>
      <dc:creator>fzink</dc:creator>
      <dc:date>2005-02-25T10:37:47Z</dc:date>
    </item>
  </channel>
</rss>

