|
On both interfaces reduce the size to say about 1350 max to take into account the ipsec overhead. Otherwise larger packets will be dropped since when they go to the interface ipsec (esp) overhead will put the packet over the 1500 allowed across most router interfaces in route:
ie do this: ip tcp adjust-mss 1350 On 3/8/07, Alex <anobre1@gmail.com> wrote: Hi everyone, _______________________________________________ firewall-wizards mailing list firewall-wizards@listserv.icsalabs.com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [fw-wiz] Firewall bake-off?, James Hampton |
|---|---|
| Next by Date: | Re: [fw-wiz] Firewall bake-off?, Carson Gaspar |
| Previous by Thread: | [fw-wiz] Fragmentation over VPN, Alex |
| Next by Thread: | [fw-wiz] Firewall bake-off?, James Hampton |
| Indexes: | [Date] [Thread] [Top] [All Lists] |