cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1501
Views
0
Helpful
7
Replies

MTU issues.

prashantrecon
Level 1
Level 1

Hi All,

Currently MTU size on the outside interface is 1500.If i change it to  1450  does it have any impact.

we have site to site ipsec vpn.Between router and firewall we have bluecoat packet shaper. on that packet we have allocated 2mbps bandwidth between

tunnel . problem is whenever user does RDP to far end pc it takes to much time .even after increasing to 3 Mbps the performance is same.

so i am deciding to change the mtu .

7 Replies 7

varrao
Level 10
Level 10

Hi Prashant,

If you decrease the MTU sizech  what it woudl mean is the firewall would drop any packet in your network which exceeds this MTU size. You might want to refer to this doc on more insight into it:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008081e621.shtml

Hope that helps,

Thanks,

Varun

Thanks,
Varun Rao

Hi Varun,

Basically user are facing when do rdp to remote side .But there are able to access sites very fastly.

Is it by changing MTU does the performances increases.?

If so what would standard MTU to set .

Hello Prashant,

Changing the MTU size is not going to help the performance of your ASA, this will only let the ASA that if receives a packet bigger than 1450 MTU size on its ethernet interface will need to drop it, but only that particular case.

If you want to do something regarding the perfomance of your network you will need to prioritize those packets (RDP) or limit the Bandwith being use on your network by policing your traffic.

Hope this helps.

Please rate helpful posts.

Juliio!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi Jcarvaja,

Blue coat packetshaper is configured between firewall and router and 2Mbps bandwidth is dedicated between

site to site vpn.Inspite user are facing issue regarding RDP to Machine.

Vendor recomended to set MTU value to 1460.

Hello Prashant,

I did an investigation on this particular issue and yes your vendor is right, seems like that is a work-around when you are unable to pass large packets through the site-to-site VPN tunnel.

This issue can result from these situations:

      -FTP traffic does not get across the tunnel.

      -Files larger than 1K are not able to go through the tunnel.

      -The remote desktop session does not come up for remote machines on the far end.  

So,the MTU could be an issue on this particular scenario so lets do what your vendor suggests.

Regards,

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thank you.i will change the value and let u know the result.

Hello Prashant,

Great I will be more than glad to see the result.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card