Created on 04-01-2021 12:14 AM Edited on 07-27-2024 11:37 PM By Jean-Philippe_P
Description
This article describes the behavior of the 'honor-df' global setting:
config system global
set honor-df enable/disable <- Enabled by default.
set hostname "FGT1"
set timezone 04
end
Scope
Any supported version of FortiGate.
Solution
FortiGate can ignore the 'do not defragment' portion of a packet.
As this is a global setting, this will only apply to the FortiGate and not to any other devices in the chain.
So regardless of the MTU set in the interfaces, FortiGate will ignore or honor the bit before the packet is forwarded.
Note: In Fortigate, there is no option for clearing a df bit in passing traffic. Fortigate can ignore it.
Consider the following scenario:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.