FGT # diag sniffer packet any "udp" 4 0 aIP datagram with ID=37572 was fragmented into two fragments:
interfaces=[any]
filters=[udp]
2015-02-18 09:28:00.095018 wan1 in 10.108.16.82.9388 -> 255.255.255.255.9388: udp 2394 (frag 37572:1472@0+)
2015-02-18 09:28:00.095111 wan1 in 10.108.16.82 -> 255.255.255.255: ip-proto-17 (frag 37572:930@1472)
# config vpn ipsec phase1-interfaceOr.
edit (name)
set ip-fragmentation pre-encapsulation <----- This option will fragment before IPsec encapsulation.
end
# config vpn ipsec phase1-interface
edit (name)
set ip-fragmentation post-encapsulation <----- This option is RFC compliant and will fragment the packets after IPsec encapsulation.
end
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.