Created on
11-24-2025
08:36 AM
Edited on
11-26-2025
04:09 AM
By
Stephen_G
| Description | This article describes how to handle an issue with traffic passing through a VXLAN where SSL traffic fails to load. |
| Scope | FortiGate. |
| Solution |
VXLAN passes all traffic except SSL traffic.
Troubleshooting steps:
If the SSL traffic is failing without UTM as well, run the following sniffer:
diagnose sniffer packet any ' host a.a.a.a ' 4 0 l <----- a.a.a.a is the destination IP.
If the sniffer output shows 'Destination unreachable (Fragmentation needed)', verify the following:
Change policy TCP-MSS as per the software switch MTU:
config firewall policy edit 1 <Policy that applies to the affected traffic> set tcp-mss-sender 1330 set tcp-mss-receiver 1330 end
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.