Answer the question
In order to leave comments, you need to log in
In what there can be a problem with work of a part of protocols?
Good afternoon.
I immediately apologize for the "many letters" further - for the sake of completeness, I hope they will help)
First, a little about the topology of the existing network:
There is a central Cisco 2921 router, it raises an IPSec tunnel with a remote office. The remote point uses Mikrotik RB750, connection through provider A. For Cisco, we use the TMG2010 proxy - it is placed in the DMZ, like the internal Cisco interface. Computers from a remote point in browsers use a proxy - Kerio Control 9 (also in DMZ).
The problem is this: the tunnel rises correctly, access via Radmin, rdp, corporate mail, antivirus update from the corporate server - they work, but http / https - "sticks" and hangs on opening the page, although pings go without problems and names are resolved correctly . FTP connection works, but files are not transferred, file transfer using Radmin does not work either. If I turn off the proxy in the browser / system - http / https start working, but, accordingly, office services working through these protocols are not available. With ftp the problem remains.
There is a 3g modem in reserve (Provider B) - when I reconfigure IPSec through it - everything works fine.
New Mikrotik models were purchased (not previously used, there were outdated models, also 750) and installed already at 2 remote points. In the first case, Mikrotik itself raises the Internet connection via PPPoE, in the second case, the provider's modem raises PPPoE, Mikrotik is behind it, and raises the VPN tunnel. The symptoms are the same in both cases.
PS when configured for the provider And the first 5-7 minutes http / https work correctly, then they stick, the file transfer does not work right away. There are about 50 more remote points configured according to the same scheme (Dlink DI800, Zyxel Zywall 200, Mikrotik 750 older versions) - there are no problems.
Can anyone suggest what could be the problem, or in which direction to look, in search of a problem? I myself have already broken my head - so far to no avail)
Thanks in advance.
Answer the question
In order to leave comments, you need to log in
Apparently you have a problem with MTU. On tunnel interfaces:
ip mtu 1400
ip tcp adjust-mss 1360 Select the
value according to which MTU the provider passes from point to point
)) the problem with MTU is visible when "something works, but something does not, or the site opens halfway" in your case, something else.
If files are not transferred via FTP, then try the passive mode, if it works, then most likely the problem is in NAT-helper, if my memory is not changed, then in cisco it is called alg and in microtek / ip firewall service-port
also show the trace from the host to server proxy.
and show the trace from the proxy server to the Internet
and show the trace from the proxy server to the host
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question