FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
cramirez
Staff
Staff
Article Id 192900

Description

 
This article describes how to solve the MSS (Maximum Segment Size) mismatch. The size of the MSS can be changed according to the policies of the FortiGate.
 
Scope
 
FortiGate.


Solution

 
cramirez_FD38560_tn_FD38560-1.jpg

Based on the previous diagram:

If the issue occurs when a user on the internal tries to visit a site on 'web server.

On policy from “internal” to “internet”
 
configure firewall policy
    edit x
        set tcp-mss-sender 1300
    end
 
Clear all sessions with these IP addresses.

 

For considerations regarding changes to MSS behavior and values, please refer to the notes in the KB article: Technical Tip: Setting TCP MSS Value