Created on 12-29-2023 08:36 AM Edited on 07-28-2024 01:29 AM By Anthony_E
Description | This article describes how to fix an ESP fragmentation issue by changing the MTU size. |
Scope | FortiGate. |
Solution |
When traffic is sent to the IPSec tunnel from the local FortiGate and it is not received by the remote FortiGate, it is possible to run a sniffer in the remote FortiGate to check the ESP packet to see if there is an error or drop in the ESP packet.
Where 192.168.10.10 is the FortiGate initiates traffic.
If there is ESP fragmentation, for example:
The user can reduce the MTU in the IPsec VPN tunnel interface in the source FortiGate 192.168.10.10:
edit <tunnel interface> set mtu-override enable set mtu <integer> next end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.