<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobility express management through IPSec in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284682#M225911</link>
    <description>Good point, I enabled it via CLI, but still the same, just loading. But&lt;BR /&gt;I can see that CLI freezes sometimes, when going through tunnel. The&lt;BR /&gt;issue with CLI starts when using autocomplete with TAB, after that it&lt;BR /&gt;freeze and I can see in PCAP TCP ACK with Analysis Flag "Previous&lt;BR /&gt;segment not captured (common at capture start)". Now I can see this&lt;BR /&gt;message on client side (browser) when i do PCAP for HTTP/HTTPS.&lt;BR /&gt;</description>
    <pubDate>Tue, 02 Feb 2021 20:43:53 GMT</pubDate>
    <dc:creator>korky</dc:creator>
    <dc:date>2021-02-02T20:43:53Z</dc:date>
    <item>
      <title>Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4283147#M225795</link>
      <description>&lt;P&gt;Hi, I have IPSec remote access VPN setup on Mikrotik router. I am not able to reach WLC/ME web interface through browser. I have no problem to open any&amp;nbsp; website HTTP/HTTPS when connected to VPN, only web management of WLC is an issue, SSH CLI works fine. I have no problem accessing web GUI on LAN, my PC and WLC management are in different VLANs. After entering &lt;A href="https://ip" target="_blank"&gt;https://ip&lt;/A&gt; to my browser, it asks me whether I trust certificate, I click yes and it loads to infinite. I tried different browsers too. I did a PCAP on client and also on router, there are duplicate ACKs and retransmits, also ICMP fragmentation needed messages. No split tunneling si set, MSS is adjusted on forward traffic to 1000, firewall is setup correctly as PC in VPN get same IP/subnet as in LAN also router is not overloaded. I think it can be connected with MTU/MSS. Access points 1815i were updated twice to 8.10.130 and now 8.10.142. Thank you for any relevant ideas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 20:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4283147#M225795</guid>
      <dc:creator>korky</dc:creator>
      <dc:date>2021-07-05T20:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4283885#M225845</link>
      <description>&lt;P&gt;Ok, https session is not loading, did you try opening http session?&lt;/P&gt;&lt;P&gt;Does WLC has proper clock settings?&lt;/P&gt;&lt;P&gt;If the certificate is self-signed, then i would recommend to regenerate and retry&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4283885#M225845</guid>
      <dc:creator>Jegan Rajappa</dc:creator>
      <dc:date>2021-02-01T20:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284638#M225909</link>
      <description>Time is set from NTP, which indicates "in sync". I can try to&lt;BR /&gt;regenerate, but in LAN it works OK. Only through tunnel it behaves strange.&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Feb 2021 19:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284638#M225909</guid>
      <dc:creator>korky</dc:creator>
      <dc:date>2021-02-02T19:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284646#M225910</link>
      <description>&lt;P&gt;Did you try http instead of https?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 19:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284646#M225910</guid>
      <dc:creator>Jegan Rajappa</dc:creator>
      <dc:date>2021-02-02T19:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284682#M225911</link>
      <description>Good point, I enabled it via CLI, but still the same, just loading. But&lt;BR /&gt;I can see that CLI freezes sometimes, when going through tunnel. The&lt;BR /&gt;issue with CLI starts when using autocomplete with TAB, after that it&lt;BR /&gt;freeze and I can see in PCAP TCP ACK with Analysis Flag "Previous&lt;BR /&gt;segment not captured (common at capture start)". Now I can see this&lt;BR /&gt;message on client side (browser) when i do PCAP for HTTP/HTTPS.&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Feb 2021 20:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4284682#M225911</guid>
      <dc:creator>korky</dc:creator>
      <dc:date>2021-02-02T20:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4285933#M226006</link>
      <description>&lt;P&gt;You can verify the MTU issue by pinging with the "do-not-fragment" bit set. All ping clients should have this option. Also try a different browser, might be a policy or cache issue on the local client.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 09:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4285933#M226006</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2021-02-04T09:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility express management through IPSec</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4287416#M226121</link>
      <description>ICMP Echo with DF had been tested before, also different browsers, clearing&lt;BR /&gt;cache and different ISPs from which I tried to establish IPSec. Finally I&lt;BR /&gt;found mistake, after examing PCAP, I saw, that MTU is too high, so it&lt;BR /&gt;seems, that change of MSS on router side is not applied. My hypothesis was&lt;BR /&gt;true. Policy which changes MSS was applied just one direction. Now it works&lt;BR /&gt;as expected, web mananagement is reachable. Thank you for all suggestions.&lt;BR /&gt;</description>
      <pubDate>Sun, 07 Feb 2021 07:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-management-through-ipsec/m-p/4287416#M226121</guid>
      <dc:creator>korky</dc:creator>
      <dc:date>2021-02-07T07:10:53Z</dc:date>
    </item>
  </channel>
</rss>

