cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
0
Helpful
2
Replies

PIX - PIX VPN

dwisidagama
Level 1
Level 1

I have PIX-PIX VPN setup. The two locations are connected with a serial T1.

Could anyone give me a hint why the VPN crashes over large file transfers?

What should I be in lookout for? I've set MTU to the same size (1500). Shouldn't VPN be up while the file is being transfered?

With thanks,

-Don

2 Replies 2

smahbub
Level 6
Level 6

Reduce the MTU to 1400 or even less. The IPSEC overhead could be crashing it. Also, make sure you are on the latest PIX code… both boxes.

cjacinto
Cisco Employee
Cisco Employee

Are you saying the PIX crashes itself when doing large file transfers? This should not be happening

and I suggest to contact the TAC with the crash dump

if ever this happens, you might need a code upgrade.

If the files just doesn't transfer but the pix is still up and the vpn tunnel is up, it is best to do a packet trace and see if the packet is big (1500) with df bit set to on. If so you might need to adjust the mtu on the hosts doing file transfer to maximum of 1400 bytes to allow for the additional 58 bytes for the ipsec header.