Question
Allow Fragmentation over IPSEC?
We have a need to allow fragmentation and reassembly of packets prior to being IPSEC encapsulated but I can' t find the appropriate command within the FortiOS CLI or GUI that wuold allow this. Essentially some of our VoIP packets between offices are getting dropped because once encapsulated they are larger than the standard 1500 MTU size. We need to be able to flag those IPSEC packets to be fragmented prior to encapsulation if the encapsulated size will end up over 1500. I know that SonicWalls have a feature called ' Enable Fragmented Packet Handling" that does this and with Cisco devices you can issue the command ' crypto ipsec df-bit clear' to clear the ' Do Not Fragment' bit in the packet header that keeps packets from fragmenting...how can I accomplish the same thing with FortiOS?
