cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5141
Views
15
Helpful
5
Replies

Cisco ASA cant ping bigger than 1000 byte

Umit AYDINLI
Level 1
Level 1

Hi,

I have a cisco asa 5520 version 8.2.

I found big problem with ping. I can't ping any internet ip with packet size bigger than 990.

I checked runing again. I see config every thing fine. I can't ping bigger than 990 byte.

How can do that. Could advice me.

C:\Users\uaydinli>ping 172.17.97.2 -l 1000

Pinging 172.17.97.2 with 1000 bytes of data:

Request timed out.

Request timed out.

Request timed out.

Request timed out.

Ping statistics for 172.17.97.2:

    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\Users\uaydinli>ping 172.17.97.2 -l 990

Pinging 213.144.97.2 with 990 bytes of data:

Reply from 172.17.97.2: bytes=990 time=1ms TTL=64

Reply from 172.17.97.2: bytes=990 time=1ms TTL=64

Reply from 172.17.97.2: bytes=990 time=1ms TTL=64

Reply from 172.17.97.2: bytes=990 time=1ms TTL=64

Ping statistics for 172.17.97.2:

    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

    Minimum = 1ms, Maximum = 1ms, Average = 1ms

C:\Users\uaydinli>

Cisco ASA 5520 Config

LILY# sh conf | inc mtu

mtu OUTSIDE_172.17.96.70 1500

mtu DMZ_172.17.97.1 1500

mtu DMZ_172.17.99.0/29 1500

mtu DMZ_172.17.98.0/28 1500

mtu DMZ_172.17.115.56/29 1500

mtu DMZ_CB 1500

mtu DMZ_St 1500

mtu DMZ_ML 1500

mtu DMZ_DT_172.17.111.64/28 1500

mtu DMZ_BT_172.17.106.60 1500

mtu DMZ_PT 1500

mtu DMZ_BD 1500

mtu BL_FW 1500

mtu INSIDE_LAN_192.168.20.3 1500

mtu INSIDE_Net_1_192.168.22.0 1500

mtu INSIDE_Net_2_192.168.24.0 1500

mtu INSIDE_Net_3_192.168.25.0 1500

mtu Voice_CME 1500

LILY#

LILY(config)# sysopt connection tcpmss ?

configure mode commands/options:

  <0-65535>  TCP MSS limit in bytes, minimum default is 0, maximum default is

             1380 bytes

  minimum    Set minimum limit of TCP MSS

LILY(config)# sysopt connection tcpmss

1 Accepted Solution

Accepted Solutions

You can apply captures using CLI;

https://supportforums.cisco.com/docs/DOC-17814

Thanks,

Varun

Thanks,
Varun Rao

View solution in original post

5 Replies 5

varrao
Level 10
Level 10

Hi Umit,

Have you tried taking captures and checked where the packets are dropping??

Varun

Thanks,
Varun Rao

Hi Again,

Im tried used adsm capture wizard. But cant capture any packet.

Please advice again.

You can apply captures using CLI;

https://supportforums.cisco.com/docs/DOC-17814

Thanks,

Varun

Thanks,
Varun Rao

Im found this problem. Im fixed, remove ip audit policy solved.

Thnks for advice.

Hi Umit,

Thats great.....well done.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking products for a $25 gift card