01-27-2012 12:11 AM - edited 03-04-2019 03:02 PM
We have been implemented guest access net which was totally seperated on Global routing table with the other site.
That was established by GRE tunnel to transport guest access traffic between backbone and that site.
However, according to requestor, they asked to investigate the GRE tunnel due to internet slowness issue.
the speed of Google page is ok such as small web traffic data, but some of heavy portal such as yahoo load speed is very slow or failed.
I thought that MTU might be caused the issue. Please, check this issue as below configuration between two sites.
(Backbone side)
ip vrf forwarding Guestnet
ip address aa.bbb.0.149 255.255.255.252
ip route-cache flow
tunnel source aaa.bbb.ccc.23
tunnel destination aaa.bbb.ccc.1
tunnel path-mtu-discovery
service-policy input Guestqos
service-policy output Guestqos
!
policy-map Guestqos
class class-default
police cir 5000000 bc 156250 be 156250 conform-action transmit
exceed-action drop violate-action drop
(branch office)
int tunnel 0
ip vrf forwarding gm-supplier
ip address aa.bbb.0.150 255.255.255.252
ip route-cache flow
tunnel source aaa.bbb.ccc.1
tunnel destination aaa.bbb.ccc.23
tunnel path-mtu-discovery
service-policy output GUESTQOS
End
akrctclcs002#sh policy-map GUESTQOS
Policy Map GUESTQOS
Class class-default
police cir 5000000 bc 156250 be 156250 conform-action transmit exceed-action
drop violate-action drop
show int tunnel 10 on backbone
-snip-
Tunnel source aaa.bbb.ccc23, destination aaa.bbb.ccc1, fastswitch TTL 255
Tunnel protocol/transport GRE/IP, key disabled, sequencing disabled
Tunnel TTL 255
Checksumming of packets disabled, fast tunneling enabled
Path MTU Discovery, ager 10 mins, min MTU 92 <-- I strongly suspected that it caused the isssue, but not sure.
Last input 00:00:01, output 00:08:54, output hang never
Last clearing of "show interface" counters 2w2d
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
-snip-
Please check it for us.
Thanks.
Solved! Go to Solution.
01-27-2012 10:56 PM
Hello,
If its a cisco vpn client, then there is a utility called "Set MTU utility". You set that according to the one set on the tunnel interface & it should work fine.
You can find that utility here Start --> Programs --> CiscoVPNclient --> SetMTU
If you are curious to know whats happening, here goes some information
A basic standard MTU size for an ethernet network is 1500 Bytes, But if the internet connection on which you the VPN client exists could be a PPPoE (kind of) which is around 1492 bytes. You can either set the MTU using SetMTU or change try changing the config on tunnel interface 1492, this may fix.
Hope this helps. Let me know if problem still persists. Will work accordingly.
Thanks
Vivek
01-27-2012 03:21 AM
hi,
If some sites work and some others don't most probably it is an MTU issue. Try hardcoding the ip mtu on the GRE tunnel interfaces on both ends. The MTU of 92 is the default minimum since you have PMTU enabled
Below is a good link that explain more about resolving MTU issues'
http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml
HTH
Kishore
01-27-2012 08:47 PM
Thanks for your inputs.
One more questions if you know, Actaully, 'ip mtu 1400' has been configured on GRE tunnel when we implment tunnel.
but IPSEC vpn client does not work properly.once we remove 'ip mtu 1400' and then IPSEC vpn client works.
we have to provide VPN connection thru GRE tunnel. in this case, Do you have any suggestions MTU size?
01-27-2012 10:56 PM
Hello,
If its a cisco vpn client, then there is a utility called "Set MTU utility". You set that according to the one set on the tunnel interface & it should work fine.
You can find that utility here Start --> Programs --> CiscoVPNclient --> SetMTU
If you are curious to know whats happening, here goes some information
A basic standard MTU size for an ethernet network is 1500 Bytes, But if the internet connection on which you the VPN client exists could be a PPPoE (kind of) which is around 1492 bytes. You can either set the MTU using SetMTU or change try changing the config on tunnel interface 1492, this may fix.
Hope this helps. Let me know if problem still persists. Will work accordingly.
Thanks
Vivek
01-29-2012 03:34 PM
Thanks for your time.
01-29-2012 06:14 PM
Happy to hear that the issue has been resolved.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: