Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

btp
Contributor

Changing MTU on one spoke tears down ALL tunnels?

I changed the MTU to 2000B (mtu-override) on wan1 port on a FG60D that connects to a FG1200D cluster with IPSEC. The config of the spoke is not changed. I did not expect anything to happen since I only changed one end, except maybe the IPSEC tunnel flapping. But after some seconds I suddenly got 1922B through with DF-bit set. So - IPSEC tunnel is apparently working.

Kind of weird, since the hub has no MTU config?

I use one phase1 and 5-6 phase2 per spoke, and have around 100 spokes. Another weird thing is that all other phase2 in this hub-and-spoke setup ALSO flapped. That is, changing MTU on ONE SPOKE tears down ALL TUNNELS? Can this be right?

Running 5.2.7.

-- Bjørn Tore

-- Bjørn Tore
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.