09-29-2011 03:23 AM - edited 03-11-2019 02:32 PM
Hi,
I have a cisco asa 5520 version 8.2.
I found big problem with ping. I can't ping any internet ip with packet size bigger than 990.
I checked runing again. I see config every thing fine. I can't ping bigger than 990 byte.
How can do that. Could advice me.
C:\Users\uaydinli>ping 172.17.97.2 -l 1000
Pinging 172.17.97.2 with 1000 bytes of data:
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Ping statistics for 172.17.97.2:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
C:\Users\uaydinli>ping 172.17.97.2 -l 990
Pinging 213.144.97.2 with 990 bytes of data:
Reply from 172.17.97.2: bytes=990 time=1ms TTL=64
Reply from 172.17.97.2: bytes=990 time=1ms TTL=64
Reply from 172.17.97.2: bytes=990 time=1ms TTL=64
Reply from 172.17.97.2: bytes=990 time=1ms TTL=64
Ping statistics for 172.17.97.2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 1ms, Average = 1ms
C:\Users\uaydinli>
Cisco ASA 5520 Config
LILY# sh conf | inc mtu
mtu OUTSIDE_172.17.96.70 1500
mtu DMZ_172.17.97.1 1500
mtu DMZ_172.17.99.0/29 1500
mtu DMZ_172.17.98.0/28 1500
mtu DMZ_172.17.115.56/29 1500
mtu DMZ_CB 1500
mtu DMZ_St 1500
mtu DMZ_ML 1500
mtu DMZ_DT_172.17.111.64/28 1500
mtu DMZ_BT_172.17.106.60 1500
mtu DMZ_PT 1500
mtu DMZ_BD 1500
mtu BL_FW 1500
mtu INSIDE_LAN_192.168.20.3 1500
mtu INSIDE_Net_1_192.168.22.0 1500
mtu INSIDE_Net_2_192.168.24.0 1500
mtu INSIDE_Net_3_192.168.25.0 1500
mtu Voice_CME 1500
LILY#
LILY(config)# sysopt connection tcpmss ?
configure mode commands/options:
<0-65535> TCP MSS limit in bytes, minimum default is 0, maximum default is
1380 bytes
minimum Set minimum limit of TCP MSS
LILY(config)# sysopt connection tcpmss
Solved! Go to Solution.
09-29-2011 06:04 AM
You can apply captures using CLI;
https://supportforums.cisco.com/docs/DOC-17814
Thanks,
Varun
09-29-2011 05:26 AM
Hi Umit,
Have you tried taking captures and checked where the packets are dropping??
Varun
09-29-2011 05:59 AM
Hi Again,
Im tried used adsm capture wizard. But cant capture any packet.
Please advice again.
09-29-2011 06:04 AM
You can apply captures using CLI;
https://supportforums.cisco.com/docs/DOC-17814
Thanks,
Varun
09-30-2011 12:56 AM
Im found this problem. Im fixed, remove ip audit policy solved.
Thnks for advice.
09-30-2011 12:58 AM
Hi Umit,
Thats great.....well done.
Thanks,
Varun
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: