Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi All,
I've run into an issue and need to engage some outside help on it.
A L2TPv3 tunnel that has been established for a number of years, suddenly dropped, well, I should say, the tunnel is up, but the traffic is not passing.
It appears from our t...
Hi All,
I will soon be turning up an iBGP connection over a GRE tunnel as a short term temporary solution.
What Id like to know is if I will need to adjust the MSS/MTU over the GRE to prevent any issues with fragmentation for our customers before we ...
Hi All,Have my hands on some new 5548UPs and looking for an stable image. It has 5.2.1.N1.6 as default, and it looks like we are up to version 7 code now.Can anyone advise on reliability of newer code?I did read the Minimum Recommended Code here but ...
All,My ISE integration is on our local domain,for example company.local. I created a rule in the authorization policy that used a static IP address, say guest.company.com for our guests to use for the redirection. When guests get the web auth redire...
Hi All,I have two issues:Is it still an issue when a wired user who is directed to the ISE CWA, is able to stay authenticated as a guest for as long as they stay connected? This is happening on our test pilot - a guest with 2 hour access on a wired c...
Configuration is very standard, use it widely within the network:
l2tp-class class-XX authentication password XX!pseudowire-class pw-XX encapsulation l2tpv3 protocol l2tpv3 class-XX ip local interface Gi 0/0! ! interface gi 0/0 descri...
Hi Gaurav,
Thanks!
Another question - the tunnel transport mtu is 1476 currently according to the "sh int tun1" command (actually MTU = 17916, and tunnel transport mtu = 1476).
Does the ip tcp adjust mss be set on the GRE interface or the pyhsical?
...
Ive read some people suffering performance issues when traffic is over standard GRE tunnels. My understanding is that once fragmentation occurs it is up to the endpoint to reassemble the packet.
So new question: If tunnel MTU is standard 1476, should...
Thanks very much for the reply. I agree, it seems there are far too many bugs released these days as updates are pushed out far too often.
Does anyone have any experience with version 6 code?
Thank you, yes I read that the external CAs will stop allow local domains on the certificates so I think its best to run company.com on our nodes and as we already have split DNS setup this works good.I guess this is probably the best way to future p...