FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Dongfang_Li_FTNT
Article Id 291563
Description This article describes how to fix an ESP fragmentation issue by changing the MTU size.
Scope FortiGate.
Solution

When traffic is sent to the IPSec tunnel from the local FortiGate and it is not received by the remote FortiGate, it is possible to run a sniffer in the remote FortiGate to check the ESP packet to see if there is an error or drop in the ESP packet.


diag sniffer packet any 'host 192.168.10.10 and proto 50' 4

 

Where 192.168.10.10 is the FortiGate initiates traffic.  

 

If there is ESP fragmentation, for example:


9074041-5.png
The original direction traffic is fragmented, but the reply traffic is fine.

 

The user can reduce the MTU in the IPsec VPN tunnel interface in the source FortiGate 192.168.10.10:


config system interface

edit <tunnel interface>

set mtu-override enable

set mtu <integer>

next

end