Mss size decreases after packet enters outside router from firewall

Answered Question
Jul 19th, 2011

Hello,  I have been googling for a lead on our current problem with no luck so far.

We have a particular application that is sending packets out our firewall to our OSSR CISCO 6509.

When the packets enter the 6509 they are fully formed with an MSS size of 1460 and have the SYN, ACK etc...

When they exit the 6509 the MSS, TSER, TSV and some other packets are completly gone.

We used monitoring sessions to find and collect the data.

I believe the issue resides at layer 3 but can't prove it right now.

How can one configure a 6509 to drop or severly reduce the size of the various portions of the packet?

Can a 6509 arbitrarily begin packet shapping based on something it detects within the packte?

No other traffic traversing this device is having this problem.

ej

I have this problem too.
0 votes
Correct Answer by andrew.prince@m... about 2 years 9 months ago

Which options are being changed/removed?

  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 5 (1 ratings)
andrew.prince@m... Wed, 07/20/2011 - 02:25

The MSS is negotiated in the TCP handshake, the lowest number wins. I'm not 100%, but I am pretty sure that the 6509 cannot perform tcp mss intercept for packets that flow thru the device, only packets originated from the device.

ronin4246 Wed, 07/20/2011 - 16:16

ok I think I need to clearify.

The packet header is being changed.

There are the normal options in the header when it enters the device but none when it exits.

This happens to all packets from the source application but only that application.

Is it possible that the 6509 is seeing a flag on the header and reacting to that by reducing/eliminating items in the header?

ej

ronin4246 Wed, 10/19/2011 - 16:12

The fix was to down grade the OS from MS 2007 to MS 2003 on the server.

ej

Actions

Login or Register to take actions

This Discussion

Posted July 19, 2011 at 10:05 PM
Stats:
Replies:4 Avg. Rating:5
Views:733 Votes:0
Shares:0
Categories: Routers
+

Related Content

Discussions Leaderboard