GRE/IPSec Tunnel Help!!!

Unanswered Question
Sep 30th, 2009

We have some routers that are going over a GRE tunnel and have IPSec encryption. THis is done over a 3G line. We were experiencing problems with certain applications being slow and changed the mtu size from 1514 to 1420. This improved the connection to our applications but now they are having issues getting to certain internet sites. Has anyone seen this issue before? Is there a fix to it?

This is our tunnel config...

interface Tunnel0

ip address 10.10.5.6 255.255.255.252

ip tcp adjust-mss 1420

tunnel source Cellular0/1/0

tunnel destination 68.16.91.195

tunnel path-mtu-discovery

!

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Peter Paluch Wed, 09/30/2009 - 09:07

Hello,

Can you be more specific about the "issues getting to certain internet sites"? Do you suspect your packets getting lost? Is the connection still slow? Can you perhaps identify some technical issue that you believe to be related to the cause of your problem?

Best regards,

Peter

Brent Rockburn Wed, 09/30/2009 - 09:25

ip tcp adjust-mss 1360

On the Cellular0/1/0 interface.

I had a similar issue and this helped.

Giuseppe Larosa Thu, 10/01/2009 - 07:35

Hello Dennis,

I agree with Brent you need to reduce further TCP MSS 1420 doesn't reflect all your encapsulation overheads (GRE 24 Bytes and IPSEC (variable depending if using tunnel mode or not) and 40 bytes IPv4 + TCP headers)

Hope to help

Giuseppe

Actions

This Discussion