VPN Connection for some hosts not working

Unanswered Question
Sep 8th, 2008

Hi guys,

I hope some one can help me here.

I have a L2L vpn. Mosts hosts on one side of the vpn can telnet http etc... to hosts on the other side. However one hosts in paticular cannot telnet ssh snmp etc.. to the other side. even though it can ping across.

I have checked the ACL and i permits all traffic across the vpn from L2L. I have done a packet capture and i can see the packets hitting the ASA. only ICMp gets through and back.

Any advice to resolve this issue would be great, debugs or similar.

Thanks

Stephen

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
singhsaju Mon, 09/08/2008 - 09:42

Hi Stephen,

If ping works then it could be a fragmentation issue . Try to adjust TCP MSS value on PIX. For ASA check the following link.

sysopt connection tcp-mss MSS_size_in_bytes

example : sysopt connection tcp-mss 1360

You can also find the exact size for your connection using extended ping utility from your workstation as explained in following link .

For PIX and router( as vpn end devices) use following link

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008081e621.shtml#Issues

For ASA

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml

HTH

Saju

Please rate if it helps

stephen.stack Tue, 09/09/2008 - 01:16

HI Saju,

Thanks for the info. I have tried all MTU settings.

So, before i adjusted anything my Max MTu from one host pinging another was 1418. I entered the commands

sysopt connection tcpmss 1300

and mtu outside 1300

this increased my overall mtu to 1470.

(i think this ia a good thing. not great with mtu stuff).

So, it is still not working. I have two key hosts that need to access services on the other side of the VPN.

They can both access services that the other needs to access, but not the services they need to access themselves. I can still see packets hitting the firewall using packet capture but thats it. I do not see any flows, xlates, connections, ACL matches, or anything.

Please advise.

Regards

Stephen

Actions

This Discussion