<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA + MSS issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019470#M919639</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the link ,  but  i was aware of it and the problem is not related to  mss-exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document says;&lt;/P&gt;&lt;P&gt;"A discovery has been made that there are a few HTTP servers on the Internet that do not honor the MSS that the client advertises".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be our case, but the server, instead of keeping a MSS of 1460 while the client is expecting 1380, it takes a MSS of 536. So we have the inverse of a mss-exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And 536  is the default MSS value before it gets changed after the MSS negociation. So for some reason the MSS proposals are dropped at the firewall , or  the server  refuse any proposal other than 1460.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 May 2008 13:03:49 GMT</pubDate>
    <dc:creator>michelcaissie</dc:creator>
    <dc:date>2008-05-28T13:03:49Z</dc:date>
    <item>
      <title>ASA + MSS issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019468#M919637</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some MSS issue with a ASA running 7.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the scenario&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client is a web browser  (IE 6 or 7 )&lt;/P&gt;&lt;P&gt;The server is Appache ( don't know the version)&lt;/P&gt;&lt;P&gt;protocol is HTTPS - 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the client and the server are on the same vlan i get the following&lt;/P&gt;&lt;P&gt;MSS values;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During  Syn - MSS  proposed  is 1460 &lt;/P&gt;&lt;P&gt;During  Ack - Syn   MSS  proposed  is 1460 &lt;/P&gt;&lt;P&gt;During Push  -  SSL  data  is  1460 bytes    as expected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if move the browser outside  a ASA  running  7.2 i get the following MSS values&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During  Syn - MSS  proposed  is 1460 &lt;/P&gt;&lt;P&gt;During  Ack - Syn   MSS  proposed  is 1380 &lt;/P&gt;&lt;P&gt;During Push  -  SSL  data  is  536 bytes    (the default values)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason the client and server  refuse to apply the proposed values&lt;/P&gt;&lt;P&gt;and the packets stays at the default values of 536 bytes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't log any errors ( mss-exceeded  or stuff like that)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the following command but it didn't change anything&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-sysopt connection tcpmss minimum 1380-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone knows what to do to get better packet size ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019468#M919637</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2019-03-11T12:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA + MSS issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019469#M919638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please have a look at this link, it should help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this post if you find it helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 09:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019469#M919638</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-05-28T09:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA + MSS issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019470#M919639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the link ,  but  i was aware of it and the problem is not related to  mss-exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document says;&lt;/P&gt;&lt;P&gt;"A discovery has been made that there are a few HTTP servers on the Internet that do not honor the MSS that the client advertises".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be our case, but the server, instead of keeping a MSS of 1460 while the client is expecting 1380, it takes a MSS of 536. So we have the inverse of a mss-exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And 536  is the default MSS value before it gets changed after the MSS negociation. So for some reason the MSS proposals are dropped at the firewall , or  the server  refuse any proposal other than 1460.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 13:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019470#M919639</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2008-05-28T13:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA + MSS issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019471#M919640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem resolved;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally the problem was on the server . A misconfigured registry was disabling the Path MTU Discovery , forcing the packet size to 536 &lt;/P&gt;&lt;P&gt;for all non-local destination IP addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ref:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows 2000/XP &lt;/P&gt;&lt;P&gt;Note: The modification of the Windows NT TCP/IP parameters involves editing the registry. This should only be attempted by experienced system administrators because mistakes can render the system unbootable. After these registry changes are done, reboot to apply the changes.&lt;/P&gt;&lt;P&gt;Disable PMTUD: &lt;/P&gt;&lt;P&gt;PMTU discovery is enabled by default, but can be controlled with the addition of this value to the registry: &lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters&lt;/P&gt;&lt;P&gt;\EnablePMTUDiscovery&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;PMTU Discovery:  0 or 1 (Default = 1)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Data Type:  DWORD&lt;/P&gt;&lt;P&gt;A "1" enables discovery while a "0" disables it. When PMTU discovery is disabled, a MTU of 576 bytes is used for all non-local destination IP addresses. The TCP MSS= 536. &lt;/P&gt;&lt;P&gt;When you set this parameter to 1 (True), it causes TCP to attempt to discover the Maximum Transmission Unit (MTU or largest packet size) over the path to a remote host. With the discovery of the Path MTU and the limitation of TCP segments to this size, TCP can eliminate fragmentation at routers along the path that connect networks with different MTUs. Fragmentation adversely affects TCP throughput and network congestion. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 17:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019471#M919640</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2008-05-28T17:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA + MSS issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019472#M919641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad to know that your problem is resolved now. It was Uncle Bill again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 06:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mss-issue/m-p/1019472#M919641</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-05-29T06:20:06Z</dc:date>
    </item>
  </channel>
</rss>

