Re: FTP over VPN



This problem I have seen before and reducing the size of the MTU solved the
problem. I don´t say it will solve your problem, but you might want to try
this.


--
----------------------------------------------------------------------------------------------------------------------------
Johan Engdahl
CCSA, CCSE, CCA, MCP | johan AT firewall1 DOT nu | http://www.firewall1.nu

"RBot" <cdhgooglegroups@xxxxxxxxx> wrote in message
news:1171289641.067398.62070@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello experts. Please advise! (Sorry for the long winded
explenation, but I want to make sure you have all of the information)

The company I work for has about 30 laptops (all are IBM ThinkPad -
Windows XP Professional) belonging to sales reps that work out of the
office. They must connect to the VPN or RRAS servers while "on the
road" in order to send orders and receive updates. The problem I am
experiencing is as follows:

ONLY a handful of machines are unable to ONLY download files using FTP
(active or passive) while connected to the VPN unless the data fits
into a single packet (If all of the data fits into a single packet,
the transmission works perfectly; and when sending orders over this
same connection, no matter the size of the transmission, it works
perfectly) (Most computers are have no problems with downloading
multiple packet transmissions, even when using the exact same internet
connection at the same time; side-by-side). This problem appears to
occur if the
data being received needs to be fragmented into multiple packets. The
computers that APPEAR to be affected are all of the machines that have
been, at one time or another, restored (although I have not verified
this completely using the restore partition on the hard drive)

I know the problem is not with the VPN, as most machines CAN use this
feature to receive updates in the mornings, and I know the problem is
not with the server as, as this issue happens EVERY time on certain
machines. That limits the issue to the individual computer, and some
setting that I am missing. Here is one thought, however I don't know
if this has anything to do with the issue I am experiencing:

I believe the problem may be a result of the MTU or MSS. The MTU on
the computers that are experiencing this problem seem to be larger
than that of the computers that are functioning properly. I have
found a way to change the MTU to a smaller size, but this doesn't seem
to resolve the issue. When using Ethereal on both client and server
machines, it shows the server stating that it will be sending packets
of a certain size (ie 1020 or so) and the client machine replies with
a confirmation that this size is acceptable. But when the server
sends the data, it is sent with larger size packets (ie 1400 or so)
and the client machine never even sees this attempt. I do not know
where to change the MSS and honestly don't know the difference between
the MTU and MSS, or if this will even make a difference.

Does anybody have any idea why this is happening? Future thanks for
all of the help!



.



Relevant Pages

  • FTP over VPN
    ... ONLY a handful of machines are unable to ONLY download files using FTP ... into a single packet (If all of the data fits into a single packet, ... computers that APPEAR to be affected are all of the machines that have ... When using Ethereal on both client and server ...
    (microsoft.public.windows.server.networking)
  • FTP over VPN MTU/MSS Issues?
    ... ONLY a handful of machines are unable to ONLY download files using FTP ... into a single packet (If all of the data fits into a single packet, ... computers that APPEAR to be affected are all of the machines that have ... I believe the problem is a result of the MTU or MSS. ...
    (microsoft.public.windows.server.active_directory)
  • Re: MTU problem DSL/CABLE Router - Firwall upgrade
    ... the Netgear was too large. ... "Setting your computer's MTU value too low would make downloading less ... efficient because a greater percentage of the packet is taken up by the ... Other computers on the Internet might not be able to handle MTU ...
    (comp.security.firewalls)
  • Re: MSS on router, why?
    ... The proper way to describe the ICMP packet which is supposed to be ... returned by a router which cannot forward the IP packet which is too ... Because ICMP was defined before Path MTU Discovery (1981 and 1990 ... fragmentation and try to use path MTU discovery, ...
    (comp.dcom.sys.cisco)
  • Re: Strange MTU Problem
    ... When I was just playing with the MTU and leaving the MRU and stuff alone, ... this is the largest sized packet you will transmit. ... As most serial connections are substantially faster than that, ...
    (comp.os.linux.networking)

Loading