<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sysopt connection tcpmss and MTU of 9216 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891142#M437414</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the clarification!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2012 16:16:35 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2012-05-09T16:16:35Z</dc:date>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891140#M437410</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a new ASA5585 as an internal firewall that will slowly replace our aging FWSM. For optimum performance it was adviced on the FWSM to set sysopt connection tcpmss to 0, even though using MTU of 1500. &lt;/P&gt;&lt;P&gt;On the new ASA are we now going to enable MTU of 9216 for the contexts. The ASA is running in transparent multicontext mode. &lt;/P&gt;&lt;P&gt;I read this here: &lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba9521.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba9521.shtml&lt;/A&gt; which advises against setting the tcpmss to 0. But if I understand it correct, that means that the MTU of 9216 is useless, right?&lt;/P&gt;&lt;P&gt;So in our case it would be needed to turn of the tcpmss feature to actually use the higher MTU?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pato&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891140#M437410</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-03-11T23:04:17Z</dc:date>
    </item>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891141#M437411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pato, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jumbo frames support:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/jk.html#wp1633967"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/jk.html#wp1633967&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;having a look at internal documentation we suggest setting MSS to 9096 (120 bytes lower tahn MTU) while typically we would set it to 40 bytes lower. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now what you need to remember that we will use lower of the two MSSes advertised by peers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 15:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891141#M437411</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-05-09T15:57:28Z</dc:date>
    </item>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891142#M437414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the clarification!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 16:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891142#M437414</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2012-05-09T16:16:35Z</dc:date>
    </item>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891143#M437415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please can you clarify the following questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I enable Jumbo frames support on an interface it is necessary to enable it on all the interfaces ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I have a cluster A/S and I enable the Jumbo frames support is it necessary to configure also the "Stateful Failover" &lt;/P&gt;&lt;P&gt;interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as the "sysopt connection tcpmss 9096" is a global system configuration is it possible to configure only 2 interfaces with mtu 9216 and leave all other interfaces to the default 1500 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roberto Taccon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 18:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891143#M437415</guid>
      <dc:creator>ROBERTO TACCON</dc:creator>
      <dc:date>2012-05-09T18:26:00Z</dc:date>
    </item>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891144#M437416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roberto. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My knowledge about this feature is from several years ago, feel free to doublecheck. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabling jumbo frame&amp;nbsp; resevation/forwarding does not increase the MTU automatically - you need to explicitly raise your MTU. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can leave failover interface as is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 19:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891144#M437416</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-05-09T19:22:36Z</dc:date>
    </item>
    <item>
      <title>sysopt connection tcpmss and MTU of 9216</title>
      <link>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891145#M437417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;This is now documented online:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ASA: Receiving and Transmitting Jumbo Ethernet Frames&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080bd7524.shtml" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080bd7524.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 22:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sysopt-connection-tcpmss-and-mtu-of-9216/m-p/1891145#M437417</guid>
      <dc:creator>Jay Johnston</dc:creator>
      <dc:date>2012-12-20T22:52:12Z</dc:date>
    </item>
  </channel>
</rss>

