Description
This article describes the behavior of the 'honor-df' global setting:
config system global
set honor-df enable/disable <- Enabled by default.
set hostname "FGT1"
set timezone 04
end
DF stands for 'Don't Fragment' Flag.
Scope
FortiGate.
Solution
FortiGate can ignore the 'do not defragment' portion of a packet.
As this is a global setting, this will only apply to the FortiGate and not to any other devices in the chain.
Regardless of the MTU settings on the interfaces, FortiGate will ignore or honor the bit before the packet is forwarded.
Note:
In FortiGate, there is no option for clearing a df bit with the passing traffic. FortiGate can ignore it.
Consider the following scenario:
Related articles
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.