Replacing pix515 with ASA5510 results into MTU problems.



Hi all,

We've replaced our old PIX 515 firewall with a newly bought ASA 5510.

Now some of our customers complain because they can not login on our
website.
We use the Verisign Certificates plugin to authenticate users on our
website.

Everything else is working exept the login procedure.

Now a helpdesk employee of some internet provider told a customer to
lower the MTU, it seemed that using some kind of application (as for
example our verisign plugin) resulted in failing connections.

The customer lowered the MTU and indeed, the problem disappeared.

Now for as far i know, i have the exactly same configuration on our ASA
as we had on our PIX.

I even allowed all ICMP on inside and outside interfaces to allow "ICMP
can't fragment (type 3, code 4)" and Path MTU Discovery.

Still, when users do not lower their MTU, they can not login.

Can anybody help me what config i should check or what debugging i
should monitor ?

Thanks in advance !

Sebastian

.



Relevant Pages

  • Re: What is the best way to login my website from another website?
    ... I've also used a solution for public domain "single sign on" scenarios where ... we've delivered a "public key" to the customer to encrypt a user name and ... we would then unencrypt it and use the the credentials to authenticate the ... least each time a new login request is issued). ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Using WSS as Extranet for Customers
    ... I missed the original post on this one, but I'm wondering why the login page wouldn't just be a plain ASP.NET page. ... With WSS installed on the server, if it was installed on the default port 80, you will need to add the path to the ASP.NET login app to your managed path list. ... We'd> like to use some of the same features for a customer extranet to track> projects and share documents. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: [PHP] Login script login
    ... Its in the comparison login for the db result. ... customer number ... If all is ok set sessions, got this ok, and proceed. ...
    (php.general)
  • Re: [PHP] Login script login
    ... Its in the comparison login for the db result. ... Having a grey brain moment here and need some advise on the logic of this, should be simple, login script. ... customer number ... If all is ok set sessions, got this ok, and proceed. ...
    (php.general)
  • Access to Server Using HTTP Through A Tunnel
    ... it's WWW Browser interface - NB This box is similar to a jet direct ... My VPN client terminates on a ASA running 7.2. ... The login is via IP address, ... I have messed around with MTU settings, ...
    (comp.dcom.sys.cisco)