There are two trains of thought on this problem, one is adjusting the MSS the other is to have path MTU discovery work as designed. Both methods are valid ones but carry some trade off decisions. Adjusting the TCP MSS ( maximum segment size ) is OK but that means burden on the router CPU to perfrom the task and having an IOS version that supports the feature. The other method I personally prefer is to adjust the MTU ( maximum transmission unit ) of the plain text or pre NAT interface of the PIX and allow "IP unreachables" from that interface ( I mention this because most folks use "no IP unreachables" which breaks path MTU discovery). If security is a concern then use an access-list that allows ICMP packet too big unreachables and blocks all other ICMP unreachable messages. The MTU on the pre nat interface can be set to 1400 bytes and that will ensure your internal systems lower their MTU appropriately and things will be good.
Why is this happening, some internet sites have bits and pieces of small data on their page and others have large chunks of data ( graphics usually ) so the web server responds with its largest allowable packet for efficiency. The problem is everything that exceeds ~1400 Bytes gets dropped at your site and the result is some sites are OK but others appear broken. You can confirm this by dropping the MTU on the workstation that is used for testing and try web browsing to all the sites again ( you will need to reboot the workstation for this to be effective).
Sorryfor not responding, work is crazy. Last week I sat all day and pondered with my isp.
Didn't get me anywhere, but I discovered the mtu settings where a mismatch. So I tried setting the modem up to 1500. This though, didn't work. So, I reduced the mtu size on both interfaces to 1492, (same size as the modem), and that gents, worked perfectly well.
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...
Attached policy provides CLI access to the Cisco 4G router over text messaging. Two files are in the attached .tar file:
2. PDF with instructions on how to load and use the .tcl file.