From: Sam Joseph (samjoseph747@hotmail.com)
Date: Fri May 27 2005 - 01:14:33 GMT-3
You are correct. It was an MTU problem. what I did to correct was,on the
1700, issued a command ip tcp adjust-mss 1452 on the LAN interface. Now
everything appears to be working.
Since it is a PPoE Encasulation, the ISP's forced MTU was 1492. The client
and web server ( Ex: www.cisco.com ) was trying to negotiate 1500 MTU. Once
I issued ip tcp adjust-mss 1452 on LAN interface of 1700, everything is
alright.
To isolate DNS issue, ran httpwatch, the DNS responded almost immediately.
Then ran a network trace on the 2003 Box, which is what shed light on this,
after your valuable input.
Thanks again,
>From: "Guyler, Rik" <rguyler@shp-dayton.org>
>Reply-To: "Guyler, Rik" <rguyler@shp-dayton.org>
>To: "'ccielab@groupstudy.com'" <ccielab@groupstudy.com>
>Subject: RE: OT --- Peculiar DNS Problem
>Date: Thu, 26 May 2005 07:55:56 -0400
>
>I will be in the minority here and not guess busy DNS servers. I have
>never
>had a DNS timeout issue in this configuration. However, what I have seen
>mulitple times is an MTU problem, especially with WinXP/2003.
>
>I suggest downloading one of the many tools or directly modifying the
>registry to change the MTU down to a smaller size on the workstation(s)
>and/or server. The DNS queries are small so they shouldn't be a problem so
>a good test here is to ping by name a site you can't open in the browser.
>
>Rik
>
>-----Original Message-----
>From: Sam Joseph [mailto:samjoseph747@hotmail.com]
>Sent: Wednesday, May 25, 2005 8:09 PM
>To: ccielab@groupstudy.com
>Subject: OT --- Peculiar DNS Problem
>
>Hi Guys, Have peculiar DNS Behaviour. Here is the Detail:
>
>Have a 1700 Series with ADSL Card For Internet Access. Have Windows 2003
>DNS
>Server functioning as a forwarder. The Windows 2003 DNS will forward the
>DNS
>requests, to ISP's DNS Server for internet name resoultion.
>
>Below is a simple topology shown
>
>ISP ------ 1700 ADSL --- Cisco 2950 Switch ------ Windows 2003 DNS Server
>and Clients.
>
>Problem:
>
>The Problem is can't visit most websites.
>
>When I try to ping www.cisco.com, it works fine. If try to visit
>http://www.cisco.com, it timesout. However, can visit
>http://www.ciscopress.com website. The 1700 Series has firewall feature
>set.
>We are yet to turn on FW functions on 1700.
>
>Any insight is appreciated.
>
>Thanks
>
>------------------------------------------------------------------------
>
>Find e-mail and documents on your PC instantly with the new MSN Search
>ToolbarFREE!
>
>_______________________________________________________________________
>Subscription information may be found at:
>http://www.groupstudy.com/list/CCIELab.html
>
>_______________________________________________________________________
>Subscription information may be found at:
>http://www.groupstudy.com/list/CCIELab.html
This archive was generated by hypermail 2.1.4 : Fri Jun 03 2005 - 10:12:03 GMT-3