Got it

Fragmentation in the IPSec tunnel

Created: Sep 29, 2020 12:59:28Latest reply: Sep 29, 2020 13:26:23 394 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,

From the documentation, the command ipsec fragmentation sets the fragmentation mode of packets to fragmentation before encryption for all IPSec tunnels.

Could I run this command for specific ipsec policy? I mean if I configure this command, could it affect other tunnels where fragmentation will do before encryption?

If yes, how should I describe ipsec df-bit in such scenario if I allow in policy ipsec fragmentation before encryption?

Could I describe there (in policy) also tcp mss value need to be 1379 bytes, but I understood that this is global parameter?

Thank you for clarifying!


Featured Answers

Recommended answer

chenhui
Admin Created Sep 29, 2020 13:26:23

Hi,
Kindly refer the explain bnelo
1. Yes, this is a global paramter, which means it will affect all the IPSec tunnels.
2. To fragment the df-bit set packets, you can run command ipsec fragmentation ignore df-bit, it allow the device ignor the Don't Fragment (DF) flag bit of original packets.
3. If you are searching a way to unfragment the packets, and no packets dropping, you an run ipsec negotiate-mtu, this comand tune th MTU value of the IPSec negotiation as you set.
View more
  • x
  • convention:

All Answers
Hi,
Kindly wait a second, we're processing on you question already.
View more
  • x
  • convention:

Hi,
Kindly refer the explain bnelo
1. Yes, this is a global paramter, which means it will affect all the IPSec tunnels.
2. To fragment the df-bit set packets, you can run command ipsec fragmentation ignore df-bit, it allow the device ignor the Don't Fragment (DF) flag bit of original packets.
3. If you are searching a way to unfragment the packets, and no packets dropping, you an run ipsec negotiate-mtu, this comand tune th MTU value of the IPSec negotiation as you set.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.