Firewall Wizards mailing list archives

Re: VPN Issue with Certs and fragmentation


From: "Bell Simon (RBNA/CIT1.12-Sbd)" <Simon.Bell () us bosch com>
Date: Wed, 26 Sep 2007 10:41:41 -0500

This issue is really frustrating me and I'm sure it's frustrating our
customers. I can't get our CA to issue a smaller cert, we're using
1024bit, so I'm gonna self sign one or setup our own CA to test this
theory. Here is a list of things and scenarios I've tested, some work
some don't:

Usually directly connecting to the broadband modem works - however in
public hotspots/hotels this isn't a viable solution.

If wired works and wireless does not, typically dropping down to WEP
from WPAx works.

Sometimes sending the CA chain (profile option) works.

Changing the MTU on the client had no effect

Changing the MTU on the public interface of the ASA had no effect

Many times a firmware upgrade on the router fixes the problem

I've also seen a doc on Dells site referring to a VLAN priority support:
http://support.dell.com/support/topics/global.aspx/support/dsn/en/docume
nt?c=us&docid=152D7D67033477DFE0401E0A5517188F&journalid=38B395C7FBD511D
ABA931F114956E124&l=en&s=gen

I'd really like to find a change that could be made on our ASAs that
would affect all our users. Working with each individual problem is a
real headache.

Any other suggestions or advice would be welcomed.

Simon

-----Original Message-----
From: John Kougoulos [mailto:koug () intracom gr] 
Sent: Wednesday, September 12, 2007 9:49 AM
To: Bell Simon (RBNA/CIT1.12)
Subject: RE: [fw-wiz] VPN Issue with Certs and fragmentation

Thanks for the reply. We're using two pair of Clustered ASAs. We're
pretty confident that the issue is client side but are still don't
really understand why a Pre-Shared Key tunnel works on networks where
a
certs fail.

it works because when you use cert mode, during IKE nego, the server
sends 
the certificate to the client for validation. The certificate doesn't
fit 
in the 1500 byte packet, therefore it fragments it.

if you don't use cert, the packet is much smaller than 1500bytes.

I think that if you use a certificate with smaller key size it might
work 
too.

I had also an issue where the traffic to a vpn concentrator was
travelling 
through an ASA and I had to use the "exceed-mss allow" workaround, so
that 
I can run IPsec over TCP through an ASA, I don't know if this is the
issue 
with your installation


Best Regards,
John.

PS. If you find a solution, please post it.... I'm still in the VPN 
concentrator boxes but soon I'll have to use the ASA too.

-----Original Message-----
From: John Kougoulos [mailto:koug () intracom gr]
Sent: Wednesday, September 12, 2007 3:09 AM
To: Bell Simon (RBNA/CIT1.12)
Cc: firewall-wizards () listserv cybertrust com
Subject: Re: [fw-wiz] VPN Issue with Certs and fragmentation

I've seen this in Cisco VPN concentrators when using IPsec over TCP
with
"Mutual Authentication". what platform are you using for vpn
termination?

Note also that in one case, while I was debugging this issue, I found
out that the problem was an issue of double fragmentation and a broken
DSL
modem in the path.

What was happenning:

a. VPN concentrator replies with a 1500 byte packet, frag , no DF
b. Packet goes to the ISP router which fragments it to 1492 + 8 to
pass
through the ADSL line
c. DSL Modem/router (even on bridging only mode) drops the 8 (+20)
byte
packet

In this case, I changed the MTU of the VPN concentrator to 1492 and
everything worked fine.

--koug

On Tue, 11 Sep 2007, Bell Simon (RBNA/CIT1.12) wrote:

We occasionally have customers call in reporting that they're never
prompted for credentials when attempting to connect to the VPN. This
happens most often when they're at a hotel/public hotspot. However,
if
they use a profile based on a preshared key instead of a cert
authentication, they connection works w/o issue. I've captured
traffic
off a failed user and it looks like during a cert auth IPSec tunnel
there's a fair amount of packet fragmentation. I'm guessing then that
a
router in-between is probably just dropping those packets causing
phase1
to fail. Has anyone else seen something similar to this? I'm thinking
dropping the MTU on either our public interface or on the client
directly.

Any other suggestions shared experiences would be great,

Simon
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: