SRX

last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  HTTP Being filtered over VPLS

    Posted 12-15-2014 11:45

    HTTP sessions when running over Juniper MPLS network do not load except for google http sites. MPLS, OSPF, RSVP, BGP, VPLS appear to filter http sessions.

    Uploaded 12-15-14 running configs for both the Zeus and EOS SRX550 Juniper Routers and Wireshark captures for http sessions to Yahoo.com and Google.com
    Ran wireshark on Laptop. Tried 4 different tests. Two with traffic processed by Juniper MPLS, Two with direct connection to vlan tagged switch. Switch directly connected to cable modem. When Juniper MPLS network is inserted between switch and laptop, http filtering takes place. Remove Juniper MPLS, full connectivity restores on HTTP sessions.

     

     

     

    Attachment(s)

    txt
    SRX550+EOS+-+12-15-14.txt   4 KB 1 version
    zip
    Wireshark Results.zip   822 KB 1 version


  • 2.  RE: HTTP Being filtered over VPLS
    Best Answer

     
    Posted 12-16-2014 00:29

    All other kinds of  traffic is working ? I'm guessing at this point that their is a MTU problem



  • 3.  RE: HTTP Being filtered over VPLS

     
    Posted 12-16-2014 02:55

    I am in agreement with MarcTB, this looks like an MTU issue.  MPLS will not fragment packets upon ingress to an LSP.  Your best bet to troubleshoot this is to just do a ping between nodes on either end of the MPLS network:

     

    ping size 1472 do-not-fragment <dest-ip>

     

    If you're unable to ping with 1472 (that's 1500 bytes minus the IP header), then your MTU is too low.  If you control the MPLS transport network, raise your MTU on those transit interfaces to account for your IP MTU, plus VLAN header(s), plus MPLS labels.  I normally set all my physical MTU in my core network to 9100 so there is almost no way I will run into an MTU problem.  All the edge-facing ports are set to the default MTU.



  • 4.  RE: HTTP Being filtered over VPLS

     
    Posted 12-17-2014 22:33

    Did you checked the suggestions EVT was giving ? or could you solve the problem in any other way ?