Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Contivity (Tcp mss and Tunnel MTU)

Status
Not open for further replies.

carlosmcse

IS-IT--Management
Nov 17, 2005
67
US
We have a mesh network all connected via Contivities 1740's and 1100's. I don't understand the tcp mss option and also the tunnel MTU option what should this be configured to? the tcp mss option is enabled on the LAN (private) and also on the LAN (Public) side of every contivity and the setting is for 1460 as for each tunnel the Tunnel MTU is enabled and the MTU is set for 1788. Should this be the correct setup? The LAN (private and public) MTU is set to 1500. If I disable the tunnel MTU the clients can't access anything on the other network.

Thanks,
 
The reason to the above post is that I find that internet browsing thru the Contivity or accessing files on the other side of the tunnel is slow for a T1 it should be allot faster.
 
The settings in our network are the same - except - we have the MSS parameters unchecked (or disabled).

I haven't given much thought to understanding what's up, so that's all I have for now.

Good luck!
 
tcp MSS clamping is for only TCP traffic. So the big question is why do you have this enabled on the public interface?? This will be ESP traffic...

Secondly your issue with internet being slow or traffic going through the BOT being slow. So what type of traffic is slow are you fragmenting packets?? This would dictate your issue on having slow traffic. So if your traffic is large TCP frames then the MSS clamping might help. If your having UDP traffic that is large traffic then TCP MSS Clamping will do no good.

I would recommend getting some sniffer traces on the contivity to see what type of traffic is going through the tunnel. Contivity depending on what code your running does support PCAP.. Use it it will help.
 
enable, then lower the tcp mss option on the private interface to 1300. I have found that often helps.

peace
 
Before you play with the MTU values, check and see if you are fragmenting packets. All of your MTU values are correct (default). They might need tuning, but only if you're fragmenting packets and dropping some.

One thing you didn't mention is errors. This is significant in my opinion. If you aren't seeing any errors, only slow traffic, then I wouldn't jump to any conclusions that your MTU values are causing this. The first thing I'd check if I was seeing slow traffic is whether or not compression was enabled on the branch office tunnel. Enabling compression can have a huge effect on throughput.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top