<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Traffic Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-traffic-problem/m-p/924677#M959589</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've got a strange Problem. I can establish a Tunnel between an PIX 515e (8.0.3) and an ASA Device 5510 7.0.6 Ping works, HTTP for example throws MSS Exceed on the ASA. PIX and ASA configured to allow mss-exceed via service Policy. The Data Size is always about 1443 Bytes. The sysopt tcpmss value is set t o1380 which should be enough for payload and IPSEC Header. The error Message says MSS Exceed MSS 1260 Data bytes 1443 ... ??? What the Hell can i do the reduce the payload. Changing the MTU size doesn't help.&lt;/P&gt;&lt;P&gt;I discover that the Problem arrives if i do an upgrade to ASA/PIXOS later than 7.0.6 because i have a second l2l tunnel to an Checkpoint device and if i upgrade the asa, this tunnel doesn't wokr for large Packets..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetings markus&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:37:43 GMT</pubDate>
    <dc:creator>helfrich</dc:creator>
    <dc:date>2019-03-11T11:37:43Z</dc:date>
    <item>
      <title>VPN Traffic Problem</title>
      <link>https://community.cisco.com/t5/network-security/vpn-traffic-problem/m-p/924677#M959589</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've got a strange Problem. I can establish a Tunnel between an PIX 515e (8.0.3) and an ASA Device 5510 7.0.6 Ping works, HTTP for example throws MSS Exceed on the ASA. PIX and ASA configured to allow mss-exceed via service Policy. The Data Size is always about 1443 Bytes. The sysopt tcpmss value is set t o1380 which should be enough for payload and IPSEC Header. The error Message says MSS Exceed MSS 1260 Data bytes 1443 ... ??? What the Hell can i do the reduce the payload. Changing the MTU size doesn't help.&lt;/P&gt;&lt;P&gt;I discover that the Problem arrives if i do an upgrade to ASA/PIXOS later than 7.0.6 because i have a second l2l tunnel to an Checkpoint device and if i upgrade the asa, this tunnel doesn't wokr for large Packets..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetings markus&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-traffic-problem/m-p/924677#M959589</guid>
      <dc:creator>helfrich</dc:creator>
      <dc:date>2019-03-11T11:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic Problem</title>
      <link>https://community.cisco.com/t5/network-security/vpn-traffic-problem/m-p/924678#M959590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the config for allowing mss-exceed. Following is an example config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list http-list permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map http match &lt;/P&gt;&lt;P&gt; access-list http-list &lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tcp-map tmap&lt;/P&gt;&lt;P&gt; exceed-mss allow&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;  class http&lt;/P&gt;&lt;P&gt;   set connection advanced-options tmap &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check for the traffic that is being denied and check if you have configured this for the right traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2007 15:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-traffic-problem/m-p/924678#M959590</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2007-12-10T15:08:40Z</dc:date>
    </item>
  </channel>
</rss>

