Firewall Wizards mailing list archives
Re: VPN Issue with Certs and fragmentation
From: "Bell Simon (RBNA/CIT1.12-Sbd)" <Simon.Bell () us bosch com>
Date: Wed, 26 Sep 2007 10:41:41 -0500
This issue is really frustrating me and I'm sure it's frustrating our customers. I can't get our CA to issue a smaller cert, we're using 1024bit, so I'm gonna self sign one or setup our own CA to test this theory. Here is a list of things and scenarios I've tested, some work some don't: Usually directly connecting to the broadband modem works - however in public hotspots/hotels this isn't a viable solution. If wired works and wireless does not, typically dropping down to WEP from WPAx works. Sometimes sending the CA chain (profile option) works. Changing the MTU on the client had no effect Changing the MTU on the public interface of the ASA had no effect Many times a firmware upgrade on the router fixes the problem I've also seen a doc on Dells site referring to a VLAN priority support: http://support.dell.com/support/topics/global.aspx/support/dsn/en/docume nt?c=us&docid=152D7D67033477DFE0401E0A5517188F&journalid=38B395C7FBD511D ABA931F114956E124&l=en&s=gen I'd really like to find a change that could be made on our ASAs that would affect all our users. Working with each individual problem is a real headache. Any other suggestions or advice would be welcomed. Simon -----Original Message----- From: John Kougoulos [mailto:koug () intracom gr] Sent: Wednesday, September 12, 2007 9:49 AM To: Bell Simon (RBNA/CIT1.12) Subject: RE: [fw-wiz] VPN Issue with Certs and fragmentation
Thanks for the reply. We're using two pair of Clustered ASAs. We're pretty confident that the issue is client side but are still don't really understand why a Pre-Shared Key tunnel works on networks where
a
certs fail.
it works because when you use cert mode, during IKE nego, the server sends the certificate to the client for validation. The certificate doesn't fit in the 1500 byte packet, therefore it fragments it. if you don't use cert, the packet is much smaller than 1500bytes. I think that if you use a certificate with smaller key size it might work too. I had also an issue where the traffic to a vpn concentrator was travelling through an ASA and I had to use the "exceed-mss allow" workaround, so that I can run IPsec over TCP through an ASA, I don't know if this is the issue with your installation Best Regards, John. PS. If you find a solution, please post it.... I'm still in the VPN concentrator boxes but soon I'll have to use the ASA too.
-----Original Message----- From: John Kougoulos [mailto:koug () intracom gr] Sent: Wednesday, September 12, 2007 3:09 AM To: Bell Simon (RBNA/CIT1.12) Cc: firewall-wizards () listserv cybertrust com Subject: Re: [fw-wiz] VPN Issue with Certs and fragmentation I've seen this in Cisco VPN concentrators when using IPsec over TCP
with
"Mutual Authentication". what platform are you using for vpn termination? Note also that in one case, while I was debugging this issue, I found out that the problem was an issue of double fragmentation and a broken DSL modem in the path. What was happenning: a. VPN concentrator replies with a 1500 byte packet, frag , no DF b. Packet goes to the ISP router which fragments it to 1492 + 8 to
pass
through the ADSL line c. DSL Modem/router (even on bridging only mode) drops the 8 (+20)
byte
packet In this case, I changed the MTU of the VPN concentrator to 1492 and everything worked fine. --koug On Tue, 11 Sep 2007, Bell Simon (RBNA/CIT1.12) wrote:We occasionally have customers call in reporting that they're never prompted for credentials when attempting to connect to the VPN. This happens most often when they're at a hotel/public hotspot. However,
if
they use a profile based on a preshared key instead of a cert authentication, they connection works w/o issue. I've captured
traffic
off a failed user and it looks like during a cert auth IPSec tunnel there's a fair amount of packet fragmentation. I'm guessing then thatarouter in-between is probably just dropping those packets causingphase1to fail. Has anyone else seen something similar to this? I'm thinking dropping the MTU on either our public interface or on the client directly. Any other suggestions shared experiences would be great, Simon _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- VPN Issue with Certs and fragmentation Bell Simon (RBNA/CIT1.12) (Sep 11)
- Re: VPN Issue with Certs and fragmentation Robby Cauwerts (Sep 12)
- Re: VPN Issue with Certs and fragmentation Bell Simon (RBNA/CIT1.12) (Sep 13)
- <Possible follow-ups>
- Re: VPN Issue with Certs and fragmentation Bell Simon (RBNA/CIT1.12-Sbd) (Sep 26)
- Re: VPN Issue with Certs and fragmentation Robby Cauwerts (Sep 12)
