Created on 12-30-2021 01:33 AM Edited on 06-06-2022 11:42 AM By Anonymous
Description |
This article describes how to enable path MTU discovery on Fortigate self-originated traffic. |
Scope |
FortiGate |
Solution |
- On 5.6 and 6.0 FortiOS lines, by default, any self-originated traffic from FGT (including proxy) has the DF bit set. So fragmentation is not allowed along the path to the server which automatically triggered path MTU discovery when the intermediate router's MTU is smaller and thus Fortigate adjusted the packet size.
- FortiOS v6.2 onwards, DF bit is not set for self-originated traffic. Path MTU discovery can be configured as below:
# config system globa |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.