01-01-2019 10:57 PM
Hello,
I've updatet our ASA to 9.10.1 and the anyconnect-client to 4.7.00136, now I receive a lot of messages:
the connections are working and I don't see any drops, but it's annoying.
Does anyone know about this or what Vlue to set?
Received large packet 1406 (threshold 1390)
01-01-2019 11:15 PM
01-01-2019 11:47 PM
Hi Mohammed,
that didn't change something, the MTU Size was the default of 1406, I've changed to 1420 and the messages still appear.
I think I need to change the treshold, or not?
01-02-2019 12:11 AM
02-22-2019 08:44 AM
02-23-2019 06:12 PM
08-28-2019 03:19 PM
Was this ever resolved?
I have this exact issue. No matter what I set the MTU to.. it's always 16 bytes too large.
12-03-2019 01:48 PM
It's probably a little late, but there is one bug that is responsible of those logs when the packets always exceed the threshold for 16 bytes:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp07143
"
When using AnyConnect 4.7.x (which supports DTLS v1.2) connecting to ASA 9.10.x/9.12.x, ....the ASA is replying to AnyConnect oMTU DPD packets with DPD responses of a different size (16 bytes larger than the DPD request).
The ASA responses are unexpected, as AnyConnect expects a DPD reply from the ASA to be the same size packet as sent by AnyConnect. This is specific to AES-GCM. AES-GCM is the default encryption for DTLS1.2."
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide