Description |
This article describes that UDP fragmentation can cause issues in IPsec when either the ISP or perimeter firewall(s) cannot pass or fragment the oversized UDP packets that occur when using a very large public security key (PSK).
The result is that IPsec tunnels do not come up. |
Scope | |
Solution |
For most configurations, enabling IKE fragmentation allows connections to automatically establish when they otherwise might have failed due to intermediate nodes dropping IKE messages containing large certificates, which typically push the packet size over 1500 bytes.
FortiOS will fragment a packet on sending if only all the following are true: - Phase 1 contains set fragmentation enable.
By default, IKE fragmentation is enabled.
To configure IKEv1 fragmentation:
# config vpn ipsec phase1-interface
IKEv2 fragmentation.
With the following implementation, if the IKE payloads are greater than a configured threshold, the IKE packets are preemptively fragmented and encrypted.
To configure IKEv2 fragmentation:
# config vpn ipsec phase1-interface |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.