[nsp] Problem with fragmented packets on 6506...

Iva Cabric ivac+cisco-nsp at mail.iskon.hr
Fri Feb 14 16:49:04 EST 2003


On Fri, Feb 14, 2003 at 03:57:53PM +0100, Iva Cabric wrote:
> 
> When some other VLAN (except VLAN 4) is used as source or destination
> everything works fine. And they all have similar configurations.
> 
> Problem was first noticed with IPSec dial-up clients, when they couldn't
> make connections to VPN concentrators, because ISAKMP packets (UDP 500,
> length > 576 bytes) couldn't pass through.
> 
> Is this problem known to someone else or should I contact TAC?

45 minutes later, ... I have found that source of problem is
"mls flow ip full", with "mls flow ip destination" it works fine.



More information about the cisco-nsp mailing list