Question
Fragmentation of ESP packets - truncated-ip
Hello everyone, I am experincing a lot of fragmentation on all my VPNs. I discovered this when we set up a new VPN over a new MPLS line and thought it was a problem in the MPLS - but that is fine. It also appears to happen on the VPNs that go over the Internet. I tried setting the tcp-mss and MTU to lower values, but this did not help. Now I heard that it may be possible disallow the fragmentation of packets. Do you know if this is possible or if there is anything else I can do? Here is what I see between my VPN peers (FGT400a to FGT50a/60b):
9.164151 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.164575 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.173824 10.24.1.1 -> 10.24.10.1: ip-proto-50 156 9.174828 10.24.10.1 -> 10.24.1.1: ip-proto-50 364 9.174828 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 364 9.183676 10.24.10.1 -> 10.24.1.1: ip-proto-50 308 9.183676 truncated-ip - 21 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 308 9.183970 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.184073 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 9.184073 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 9.265988 10.24.1.1 -> 10.24.10.1: ip-proto-50 84 9.278419 10.24.10.1 -> 10.24.1.1: ip-proto-50 108 9.278419 truncated-ip - 19 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 108 9.287059 10.24.10.1 -> 10.24.1.1: ip-proto-50 244 9.287059 truncated-ip - 18 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 244 9.287436 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.295359 10.24.10.1 -> 10.24.1.1: ip-proto-50 1460 9.295359 truncated-ip - 19 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1460 9.296935 10.24.10.1 -> 10.24.1.1: ip-proto-50 460 9.296935 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 460 9.297291 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.303517 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.303517 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.309656 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.309656 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.310627 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.312327 10.24.10.1 -> 10.24.1.1: ip-proto-50 724 9.312327 truncated-ip - 15 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 724 9.318821 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.318821 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.319606 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.325128 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.325128 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.328197 10.24.10.1 -> 10.24.1.1: ip-proto-50 836 9.328197 truncated-ip - 18 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 836 9.328880 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.334591 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.334591 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.340721 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.340721 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.340923 10.24.10.1 -> 10.24.1.1: ip-proto-50 172 9.340923 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 172 9.341633 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.347794 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.347794 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.348879 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.351979 10.24.10.1 -> 10.24.1.1: ip-proto-50 988 9.351979 truncated-ip - 18 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 988 9.358363 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.358363 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.359311 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.364560 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.364560 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 9.369774 10.24.10.1 -> 10.24.1.1: ip-proto-50 1268 9.369774 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1268 9.370619 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.374457 10.24.10.1 -> 10.24.1.1: ip-proto-50 1140 9.374457 truncated-ip - 14 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1140 9.377278 10.24.10.1 -> 10.24.1.1: ip-proto-50 724 9.377278 truncated-ip - 21 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 724 9.377864 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 9.384344 10.24.10.1 -> 10.24.1.1: ip-proto-50 1420 9.384344 truncated-ip - 17 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1420 9.481649 10.24.10.1 -> 10.24.1.1: ip-proto-50 116 9.481649 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 116 9.482494 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 11.638381 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 11.638381 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 11.638849 10.24.1.1 -> 10.24.10.1: ip-proto-50 92 15.635853 10.24.1.1 -> 10.24.10.1: ip-proto-50 92 15.669933 10.24.10.1 -> 10.24.1.1: ip-proto-50 100 15.669933 truncated-ip - 14 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 100 15.731477 10.24.1.1 -> 10.24.10.1: ip-proto-50 132 16.044901 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 16.044901 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 16.108037 10.24.1.1 -> 10.24.10.1: ip-proto-50 148 16.154262 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 16.154262 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 18.405066 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 18.405066 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 92 18.405469 10.24.1.1 -> 10.24.10.1: ip-proto-50 92 22.615196 10.24.10.1 -> 10.24.1.1: ip-proto-50 84 22.615196 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 84 22.615595 10.24.1.1 -> 10.24.10.1: ip-proto-50 84 22.634223 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 22.634223 truncated-ip - 20 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 76 22.635951 10.24.10.1 -> 10.24.1.1: ip-proto-50 356 22.635951 truncated-ip - 21 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 356 22.642641 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 22.642641 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 22.643239 10.24.1.1 -> 10.24.10.1: ip-proto-50 76 22.668604 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 22.668604 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 22.674708 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468 22.674708 truncated-ip - 16 bytes missing! 10.24.10.1 -> 10.24.1.1: ip-proto-50 1468Thanks for reading! stephan