Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: VPN fragmentation - How to check if SRX send fragments

$
0
0

Hi Ashvin,

 

Please find the answers below for the queries you had:

 

Could the packets be fragmented by an intermediate device/router as well, since TCP MSS has already been set to 1300 and assuming MTU on the SRX egress interface is default?

 

Hemant:Yes , the packets (ESP in this case) can be fragmented by intermediate router/L3 device.

 

Also, just to confirm the fragmented packets seen on the remote side are TCP?

Hemant: So can you please let me know is it the fragmented ESP packets seen on remote end or is it the plain text fragmneted packet? where exactly the pcap has been applied to check the fragmneted packets.

 

 

In order to look into the details firsdt you need to identify is it the packet fragmented post encryption or is it before encryption?

 

Let me know the details.

 

regards

Hemant

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>