MTU size VPN Tunnel

MTU size VPN Tunnel

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
MTU size VPN Tunnel julian.berger 07-13-2006
Posted by on July 13, 2006, 10:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello everyone,
I experienced several MTU-related problems on site-to-site vpn tunnels,
e=2Eg. certain applications work well whereas others crash or don=B4t work
at all.

I did some tests but still MTU size is a mystery to me. I assumed, that
a ping from different clients from LAN A through VPN to server in LAN B
with don=B4t fragment bit set should result in the same possible maximum
packet size, but I experienced different sizes. How is max packet size
calculated? Of course it depends on the kind of tunnel etc., but why do
I get different max sizes?

Most tunnels I have tried were configured between two Cisco 1841, some
parts of configuration as following:
.=2E.
ip tcp path-mtu-discovery
.=2E.
crypto ipsec df-bit clear
.=2E.
interface Tunnel0
ip address 10.200.200.2 255.255.255.252
ip ospf authentication-key 7 xxx
ip ospf cost 10
ip ospf mtu-ignore
qos pre-classify
tunnel source 17.0.0.2
tunnel destination 17.0.0.1
tunnel mode ipsec ipv4
tunnel protection ipsec profile XXX
!
interface FastEthernet0/0
description Standleitung
ip address 17.0.0.2 255.255.255.0
ip mtu 1400
speed 100
full-duplex
!

I changed several settings above, such as "ip tcp path-mtu-discovery"
on or off etc., but still I didn=B4t get an result that fits to my
calculations...
Any tips, suggestions and also further readings are appreciated.
Thanks,
Julian


Similar ThreadsPosted
Sometimes a tunnel... sometimes not February 8, 2005, 12:14 pm
VPN tunnel through GPRS August 25, 2005, 10:10 am
FVS318v3 to FVS318v1 tunnel April 15, 2005, 12:47 pm
Tunnel established, but no ping February 25, 2006, 9:52 am
reaching router thru vpn tunnel March 21, 2006, 10:15 am
VPN tunnel between 2 sbs 2003 servers June 27, 2006, 10:54 am
Multiple VPN Tunnel and Router June 30, 2006, 6:07 am
VPN tunnel between Dlink DFL-700 and Cisco January 18, 2007, 2:57 pm
VPN Tunnel and VPN Client at same time May 10, 2007, 11:07 am
problem with vpn tunnel between two zywall 35 August 8, 2007, 12:22 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map