Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: VPN fragmentation - How to check if SRX send fragments

$
0
0

Hi,

 

Could the packets be fragmented by an intermediate device/router as well, since TCP MSS has already been set to 1300 and assuming MTU on the SRX egress interface is default?

Also, just to confirm the fragmented packets seen on the remote side are TCP?

 

Setting the IPSec DF bit to copy may indicate which hop cannot pass the packet size provided ICMP Type 3 Code 4 is not filtered.

 

Useful links:

http://rtoodtoo.net/ipsec-tcp-mss-df-bit-and-fragmentation-in-srx/

http://kb.juniper.net/InfoCenter/index?page=content&id=KB25625&actp=search

 

Cheers,

Ashvin


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>