The vsat link between locationA to LocationB have been secured using ipsec. I have a problem printing across an ipsec-secured link. Every other traffic flows correctly but when i try printing from locationA to LocationB, only the first line prints. the other lines fail to print. When i remove ipsec from the routers, the printing is successful. I would appreciate any suggestions. thanks
I wonder if the problem is a max packet size issue. When applying IPSec the headers that are added to the packet increase the size of the packet. If the packet being sent from the end station is already max size (or close to it) the IPSec headers may make the packet too large. If the do not fragment bit is set (as it frequently is on TCP packets) it will cause the packet to be discarded.
A solution for this problem that I have used with success is to configure ip tcp adjust-mss on the LAN interface where end station traffic enters and leaves the router. You may need to experiment some to find the optimum size. In situations where I use IPSec with GRE I have found a value about 1375 to be optimum. You can experiment and see what is best in your situation.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...