Hi guys,
Today I installed 2 ASA 5505s to replace some EOL Nortel routers. Install went smoothly and pretty much everything worked, VPN established, connectivity out to the Internet outside the tunnel, etc.
However, when pinging across the VPN to the remote site's inside interface (and hosts on the LAN there) I am getting drops sporadically, say every 12 packets, solid for 10, drop 5, then solid again for 15...
Log on both sides doesn't complain about anything, just see normal ICMP builds and teardowns. For troubleshooting I even tried to disable the ASA's "basic threat detection" and opened the firewall to all ip traffic to eliminate that as the issue. Still got the drops. Assuming maybe the processor was over worked I disabled all the debug logging too, still got the drops. I eventually removed the ASAs and called my hosting provider on the other side of the world to plug the Nortel's back in.
Of course the Nortel's worked perfectly, no drops at all.
I am wondering what I can do to troubleshoot this. My gut feeling is a fragmentation / MTU issue on the tunnel. Anyone else experience this?
Configs below.
Today I installed 2 ASA 5505s to replace some EOL Nortel routers. Install went smoothly and pretty much everything worked, VPN established, connectivity out to the Internet outside the tunnel, etc.
However, when pinging across the VPN to the remote site's inside interface (and hosts on the LAN there) I am getting drops sporadically, say every 12 packets, solid for 10, drop 5, then solid again for 15...
Log on both sides doesn't complain about anything, just see normal ICMP builds and teardowns. For troubleshooting I even tried to disable the ASA's "basic threat detection" and opened the firewall to all ip traffic to eliminate that as the issue. Still got the drops. Assuming maybe the processor was over worked I disabled all the debug logging too, still got the drops. I eventually removed the ASAs and called my hosting provider on the other side of the world to plug the Nortel's back in.
Of course the Nortel's worked perfectly, no drops at all.
I am wondering what I can do to troubleshoot this. My gut feeling is a fragmentation / MTU issue on the tunnel. Anyone else experience this?
Configs below.