Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5505 and support for TCP Windows Scaling

Hi all:

We have a small office (15 users) protected by an ASA 5505 running 8.2(5).  The problem we are having is downloading large files from to Office 365 (really SharePoint in MS cloud).  They get interrupted and the connection is dropped. 

I have looked into this and it seems the problem concerns the TCP Window scaling or autotuninglevel and its support by upstream routers from the user. If I open an elevated Command prompt on my machine and execute the following the large files download fine through the ASA

netsh int tcp set global autotuninglevel=disabled

Putting it back to the default setting again will cause the file to not download

netsh int tcp set global autotuninglevel=nomal.

Also if I swap out the ASA 5505 using a consumer router/FW I have no problems with the larger files.

Question, is there a way to activate windows scaling on the ASA which my consumer router/FW seems to support?  Will upgrading to a higher software version of the ASA help?  I am using 8.2(5)?  I am hoping this is a fairly common problem but I can’t seem to find an easy solution online.  Thanks so much  -Bob

  • Firewalling
2 REPLIES
Cisco Employee

Hello; I would defintely open

Hello;

 

I would defintely open a TAC case on this one. Updating the code on the firewall is not going to help.

Captures and other troubleshooting steps need to be performed.

 

Mike.

Mike
New Member

I have exactly the same

I have exactly the same problem on an ASA 5505 with 8.2(1). I believe it is a bug but not having a current contract prevents me from being able to upgrade the firewall. I found the following references to the problem and the workarounds do work but it should ideally be fixed on the firewall. 

http://prowiki.isc.upenn.edu/wiki/TCP_tuning_for_broken_firewalls

http://serverfault.com/questions/337039/cisco-asa-5505-tcp-window-scaling-rfc1323

http://www.richweb.com/book/export/html/88 - TCP Window Scaling Problems with broken Firewalls

263
Views
5
Helpful
2
Replies