Hi,Do I understand well that if you send bigger ICMP packets through the tunnel, those are dropped as well?If it is true it looks like this is a pure fragmentation issue.In this case there is nothing to do with MSS and "df-bit clear".Only fine tuning...
Hello Cassio,Do you need HSRP on the outside interfaces?And do you insist to keep them to use this?What if you try to implement this:Dynamic Multipoint IPsec VPNs (Using Multipoint GRE/NHRP to Scale IPsec VPNs)http://www.cisco.com/en/US/tech/tk583/tk...
Hi,What is in the UserVPN access-list?This determines what should go through the tunnel from the client.Also what is the exact routing and NAT 0 config?Is there any ?
Hi Mattias,If I got well the IP aaa.bbb.ccc.82 is the physical IP of the PIX and th IP aaa.bbb.ccc.90 should be an outside IP of a server behind the PIX.In this case you'll only need th create a static entry in the PIX to answer these queries, like...