<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Smells like an MTU issues to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870847#M166904</link>
    <description>&lt;P&gt;Smells like an MTU issues to me.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Try an extreme value like the below is see if it resolves it, and then remove the command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;sysopt connection tcpmss 1000&lt;/PRE&gt;</description>
    <pubDate>Sun, 19 Jun 2016 20:10:21 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-06-19T20:10:21Z</dc:date>
    <item>
      <title>ASA Slowing down a single web page load</title>
      <link>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870846#M166903</link>
      <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am experiencing a unique problem. Before explanations, I'll post this schema below so that you can have an idea about the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/dessin1.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have external clients that try to access a web page which is on our internal WebServer illustrated before on port 444 which&amp;nbsp;forwards to the 443 (the real port). While doing my tests with the ASA as a firewall instead of the old iptables firewall, I can get to the&amp;nbsp;page hosted on our server from an external network (my 4G for example or any other network) using a navigator and can authenticate my self, so the NAT here is really forwarding the mapped port to reach the real port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My problem is that after the authentication process the web page don't load or load very very slowly and sometimes some parts of the page don't load at all (It's very "random" without touching to the settings)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do you have any idea from where the problem might be coming ?&lt;/P&gt;
&lt;P&gt;If it can help, i can post my NAT configuration :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (outside,inside) source static any any destination static interface VESR003 service 444 444- unidirectional&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;444 : is a service that have as a source port (1-65535) and destination port 444&lt;/P&gt;
&lt;P&gt;444- : is a service that forward (source port 444) to (destination port 443) after translation&lt;/P&gt;
&lt;P&gt;I don't know if I am doing the port forwarding properly but it seems that this is working as soon as I can reach the authentication page and authenticate on the htaccess box.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For your information : i'm using ASA version 9.2.4 and ASDM 7.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870846#M166903</guid>
      <dc:creator>abdou.bekk1</dc:creator>
      <dc:date>2019-03-12T07:54:46Z</dc:date>
    </item>
    <item>
      <title>Smells like an MTU issues to</title>
      <link>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870847#M166904</link>
      <description>&lt;P&gt;Smells like an MTU issues to me.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Try an extreme value like the below is see if it resolves it, and then remove the command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;sysopt connection tcpmss 1000&lt;/PRE&gt;</description>
      <pubDate>Sun, 19 Jun 2016 20:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870847#M166904</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-06-19T20:10:21Z</dc:date>
    </item>
    <item>
      <title>Hi Philip,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870848#M166905</link>
      <description>&lt;P&gt;Hi Philip,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I just did try the command but it didn't resolve the issue. This is the only site which blocks on loading.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 06:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870848#M166905</guid>
      <dc:creator>abdou.bekk1</dc:creator>
      <dc:date>2016-06-20T06:49:54Z</dc:date>
    </item>
    <item>
      <title>Also, I noticed that when I</title>
      <link>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870849#M166906</link>
      <description>&lt;P&gt;Also, I noticed that when I launch a "netstat -ano" on Windows to check ports and active connections, &amp;nbsp;I can see that when it comes to the public IP of the website (outside ASA interface IP) it stucks on "SYN_SENT".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Output on Windows :&lt;/P&gt;
&lt;P&gt;TCP &amp;nbsp; &amp;nbsp; 192.168.199.41:2734 &amp;nbsp;212.xxx.xxx.xxx:444 &amp;nbsp; &amp;nbsp;SYN_SENT &amp;nbsp; &amp;nbsp;4756&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP &amp;nbsp; &amp;nbsp; 192.168.199.41:2735 &amp;nbsp;212.xxx.xxx.xxx:444 &amp;nbsp; &amp;nbsp;SYN_SENT &amp;nbsp; &amp;nbsp;4756&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP &amp;nbsp; &amp;nbsp; 192.168.199.41:2736 &amp;nbsp;212.xxx.xxx.xxx:444 &amp;nbsp; &amp;nbsp;SYN_SENT &amp;nbsp; &amp;nbsp;4756&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TCP &amp;nbsp; &amp;nbsp; 192.168.199.41:2737 &amp;nbsp;212.xxx.xxx.xxx:444 &amp;nbsp; &amp;nbsp;SYN_SENT &amp;nbsp; &amp;nbsp;4756&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 08:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slowing-down-a-single-web-page-load/m-p/2870849#M166906</guid>
      <dc:creator>abdou.bekk1</dc:creator>
      <dc:date>2016-06-20T08:19:52Z</dc:date>
    </item>
  </channel>
</rss>

