Some days ago a weird issue popped up. One of our client complain about website access issue. From their LAN network some of their user unable to access some websites but all are accessible from other Network. Than we’re checked DNS, Routing, Firewall Filters and related things but didn’t found any mentionable reason. The Interesting subject is; it was not happening for all users. Some users able to browse but some are not. Than we captured the packet and found different segment size generating from different workstation after that we fixed tcp mss on router interface.

Resolution for IOS (Set ip tcp mss on LAN interface):
Router(config)# interface gi0/0/1
Router(config)# ip tcp adjust-mss 1440

Details about Tcp mss :

