Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA5505 8.2(3) has trouble browsing websites - PMTU-D errors

Hi,


This one has been puzzling me a bit.

We have been having continuous MTU issue with suring certain website. Our MTU is set to 1454 on a PPoE connection (which works with a laptop directly connected) and when I try to browse certain website (like www.cisco.com) I get the following errors on the sys log

PMTU-D packet 1420 bytes greater than effective mtu 1050, dest_addr=[WANIP], src_addr=[Random website], prot=tcp

PMTU-D packet 1300 bytes greater than effective mtu 1050....

I know that PMTU relies on ICMP which I have allowed and I have also made sure that the default inspection has ICMP and ICMP Error ticked in ASDM.

I know alot of people have these issues with site2site VPN (my site to site vpns are fine its just external website browsing)

I am at a bit of a loss and any help would really be appreciated.

Cisco also has an article about this but with my version of ASA "exceed-mss allow" seems to be a default setting.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml

*attached current config*

Cheers!

5 REPLIES
New Member

Re: ASA5505 8.2(2) has trouble browsing websites - PMTU-D errors

sorry quick update I am running 8.2(3) not (2)

Cisco Employee

Re: ASA5505 8.2(2) has trouble browsing websites - PMTU-D errors

Some layer 3 device in the path has a lower MTU configured. You can try to change the MTU on the firewall and see if this helps. This will increase the nubmer of packets.

conf t

mtu outside 1050

-KS

New Member

Re: ASA5505 8.2(2) has trouble browsing websites - PMTU-D errors

Thanks for your response.

I tried to drop the MTU down as low as that but still no success. I can still see the PMTU-D errors and I started to get ICMP drops

4    Dec 01 2010    07:55:29                        No matching connection for ICMP error message: icmp src outside:ExternalIP dst inside:WANIP (type 11, code 1) on outside interface.  Original IP payload: udp src WANIP dst ExternalIP

The ASA is directly connected to a ONU for internet access and its using PPoE. The static IP is assigned automatically.

New Member

Re: ASA5505 8.2(2) has trouble browsing websites - PMTU-D errors

On the ASDM when I go to Firewall -> Advanced -> Fragment I see the below.

Interface: inside
    Size: 200, Chain: 24, Timeout: 5, Reassembly: virtual
    Queue: 0, Assembled: 0, Fail: 1, Overflow: 0
Interface: outside
    Size: 200, Chain: 24, Timeout: 5, Reassembly: virtual
    Queue: 0, Assembled: 282, Fail: 13235, Overflow: 0

Outside and interface are both set to
Size 200
Chain Length 24
Timeout 5

Not sure if that helps.

Cisco Employee

Re: ASA5505 8.2(2) has trouble browsing websites - PMTU-D errors

That sure helps.

You can add the following and see if it helps.

hostname(config)# fragment size 2000 outside

1761
Views
0
Helpful
5
Replies