We have a VPN btw ASA and Cisco 871 .This ispsec tunnel is up and functional , i can ping the Devices from both sides without any issues , but when we use Xterm or any other chatt protocl we get kiccked off at times , so when i ran a Test tunnel from SDM , i get a report "A ping with data size of this interface MTU size and " Do not fragment" bit set to other end VPN devie is failing , this may happen if there is alesser MTU network which drops the Do not fragment packets " .
My suspicion is branch office router 871 , which has only this tunnel where are main office ASA has 13 more similar tunnels that are fully funtional .
Things that i have tried ,
changing MTU to 1200 on the Fast ethernet of (where tunnel is terminated on 871 router)
TCP-adjust to 1200
When i ping from a desktop that is behind ASA to yahoo.com with -f -l , last respons i get is at 1272. But on similar test from behind 871 goes without any issues uptill 1400 + .
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...