Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Cisco 3845 Integrated Services Router -- Browsing problem |
|---|---|
| Date: | Wed, 21 Sep 2005 11:55:36 +1200 |
Did your problem get resolved after changing MTU/MSS? From tcpdump it looks like you never got syn-ack back. I would not expect it to ne MTU issue. -----Original Message----- From: Jiju Susmer [mailto:jijususmer@yahoo.com] Sent: Tuesday, 20 September 2005 10:33 p.m. To: Jiju Susmer; Sasa Rasovic; firewalls@securityfocus.com Subject: Re: Cisco 3845 Integrated Services Router -- Browsing problem Hi, I have attached the dump of the trace what lead to the fix of this problem. I had to recreate this environment to show what all things might go wrong in networking. The environment here has two ISPs connected via Linux Box as Firewall. The connction was tried to a sql server called examplehost. -- JS --- Jiju Susmer <jijususmer@yahoo.com> wrote:
At last it has been confirmed as: Its a typical cisco ios bug..the solution is to enforce the router to handshake at 1400(mss value).if the mss value is set to default , the packets were getting dropped (coz of the bug)on the internet (and there is no way we can trace it..a bit simple but complicated one.|:) -- JS --- Sasa Rasovic <sasarasovic@hotmail.com> wrote:I suppose you should try adjusting your MTU andmssof transit packets on the public interface. for example: ip tcp adjust-mss 1400 ----- Original Message ----- From: "Jiju Susmer" <jijususmer@yahoo.com> To: <firewalls@securityfocus.com> Sent: Tuesday, August 30, 2005 6:30 AM Subject: Cisco 3845 Integrated Services Router -- Browsing problemHi, I have a client who installed CISCO 3845 ISR to connect to the internet via a leading ISP. Buthehasproblem in accessing Certain sites, sayGoogle.comcomes fast and works fine, but yahoo, rediff etc hangs. One of the major features of this series routerisNetwork Admission Control, but its turned off.Contentfilter is also off. To see is not ISP problem we replaced the routerwitha lower series (2500), it worked fine with nochangesin Workstation settings. I know that this request doesn't belong here inthislist, but as the members of this group aredealingwith network, I suppose some one may have hadthisproblem and can help me solving it. Any luck? Thanks -- JS____________________________________________________Start your day with Yahoo! - make it your homepagehttp://www.yahoo.com/r/hs__________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com
__________________________________
Yahoo! Mail - PC Magazine Editors' Choice 2005
http://mail.yahoo.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | re: Trace route query, Robert MacDonald |
|---|---|
| Next by Date: | Re: Re: Firewall Inquiry- Enterprise Level Security, gmail |
| Previous by Thread: | Re: Cisco 3845 Integrated Services Router -- Browsing problem, Jiju Susmer |
| Next by Thread: | Re: Netscreen VPN route to VPN, Jordan Dohms |
| Indexes: | [Date] [Thread] [Top] [All Lists] |