Mailing List ecs-isp@2rosenthals.com Archived Message #142

From: "Massimo S." <ecs-isp@2rosenthals.com> Full Headers
Undecoded message
Subject: issue with Injoy FW (4.2.2) and a VPN tunnel
Date: Wed, 13 Jan 2021 18:52:25 +0100
To: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

Hi all,

i've an issue with an Injoy FW VPN tunnel:


SITE A
SITE B
SITE C

SITE A communicate correctly with SITE C and of course SITE C to SITE A

SITE B communicate correctly with SITE A and of course SITE A to SITE B

SITE B and SITE C have issues i can ping everything in the 2 lans
from lan of SITE B to lan of SITE C and viceversa

but all protocols have issues
it seems that only very small packets do work between SITE B and SITE C
(and viceversa)

e.g. if a copy from a folder a very small file (e.g. 1KiloByte file) from
SITE C to SITE B it works
if i copy a bigger file it does not work and it seems to wait forever

in the past SITE B to SITE C and vice versa communications worked correctly

both SITE B and SITE C (like also SITE A) use MD5 as auth header
and 3DES as encrpytion, ip compression DEFLATE
preshared secret and client-Xauth

i've of course tried to disable compression, but nothing changes/no improvement

i'm running out of idea
it seems like an MTU issue
the 2 FW machines runs eCS2.2b and have MTU 1500 on the WAN and lan NIC
and that's the right MTU as also suggested by the ISP


any help?

thanks

massimo

Subscribe: Feed, Digest, Index.
Unsubscribe
Mail to ListMaster