cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
383
Views
0
Helpful
1
Replies

Cannot RDP through IPSEC between Firepowers 1010 and 1140

User9999
Beginner
Beginner

Hi All

 

I cannot RDP nor smb or access resources over an IPSec VPN tunnel between 2 Cisco firepowers, one is 1010 the other 1140

to note:

- I can ping fine both ways

- ACL not an issue as policy is to allow any port on both ends and ping works

- IPSEC configured on both towards Azure VPN gateway, and on both these tunnels RDP is possible

I suspect the MTU maximum session size is the culprit.. when I ping with packets less than 1350 (size changes, but varies between 1350 and 1400) I get the below response: ping -l 1400 192.168.1.1 -f ----> Packet needs to be fragmented but DF set

If so, how to configure the mss through Flexconfig Sysopt_basic ? there are no templates on the Firepowers.. and the CLI is too basic..

If not, what might be the issue?

 

Thank you

 

1 Reply 1

MSakr
Beginner
Beginner

Hi All

 

Seems a firewall in between that was blocking traffic ..

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers