SSL (SVC) VPN large packets

Unanswered Question
Nov 14th, 2007

Hi,

In the ASA log, we are seeing the following error:

Error Message %ASA-3-722036: Group group User user-name IP IP_address Transmitting

large packet length (threshold threshold).

I presume our server is sending large packets to the SSL client? Has anyone else encountered this?

Thanks,

Mark.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 5 (1 ratings)
networkdvd Tue, 11/20/2007 - 07:46

Hi,

Thanks for the reply. Unfortunately I am not using the AnyConnect client. I am using ASA 7.2 with the SVC client.

bcoverstone Sun, 09/23/2012 - 11:22

I know this post is 5 years old, but this problem is still cropping up from time to time with no explanation.  Specifically, myself and others have an issue with a large packet length of 1410, with a threshold of 1406.  Unfortunately, you can't change the MTU because the maximum is 1406.  This doesn't even make sense.

I did find one possibility.  A troubleshooting article showing the ASA transmitting packets that exceeded the MTU could be fixed by running:

   svc compression none

But will this also fix the received packets?

jportugu Thu, 09/27/2012 - 19:14

Hi Brian,

The old SSL client is not longer supported, it is legacy.

At this point, I would suggest the AnyConnect client, since it introduces the command: 

[no] svc mtu size

Which only affects the AnyConnect sessios. The old SSL VPN Client (SVC) does not suppor it.

An example:

ASA(config)# group-policy AnyConnect attributes

ASA(config-group-policy)# webvpn

ASA(config-group-webvpn)# svc mtu 1200

Thanks.

Portu.

Please rate any helpful posts.

Actions

Login or Register to take actions

This Discussion

Posted November 14, 2007 at 3:37 AM
Stats:
Replies:4 Avg. Rating:5
Views:2044 Votes:0
Shares:0
Tags: No tags.

Discussions Leaderboard