Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Can' t ping oversized icmp traffic

Hi We have 2 subnet with 2 fortigate bridged with VPN ipsec. When I try to ping oversized packet between the 2 subnet that don' t work. But standard ping work. ping 192.168.5.5 -l 2048 I need this to troubleshoot a network problem. (http://www.eggheadcafe.com/microsoft/Windows-Group-Policy/31759765/userenv-event-id-1054--userenvlog-dsgetdcname-failed-with-59.aspx) Thank
15 REPLIES 15

I put the tcp-mss to 1400 but it did nothing. I forget to say that I have activated the ipsec tunnel as an interface.
Not applicable

I did a test, I create a new VPN between two FortiGate which are connected by a cable RJ45. The oversized packet work. Also I ping each wan interface and the maximum size I' ve got is 1464. Sounds like the internet line. But I don' t know if it' s the Fiber or DSL. I' ll do other test from home. In fact we have 3 fortigate. 1 is bridged with 2 via VPN ipsec (Fiber, DSL) 1 is bridged with 3 via VPN ipsec (Fiber, DSL) 2 is bridged with 3 via RJ45 cable It seams
Not applicable

The DF bit is not set. I' m not sure what you talk about source? All I can say is that all computers of the two network have the same behavior.
ede_pfau
SuperUser
SuperUser

IMHO you are focusing on the wrong device. The router(s) which interfaces to the WAN line(s) are not set up correctly if they prohibit large packets. There is an overhead of 28 bytes (not bits) for the UDP encapsulation so packets have to be fragmented when leaving the WAN interface. I don' t think you should manipulate the FGTs to force a smaller packet size - all it does it fragment earlier. And then the router blocks fragmented packets again. So it' s either your router or the router port of your ISP which you have to check - they need to allow fragmented packets.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

The router is the fortigate. Fortigate is directly linked to the dsl modem. Probably that my ISP how limit the large packets... I' ll check for a workaround solution... Thank
emnoc
Esteemed Contributor III

did you try a ping with the DF bit set? and not thru the tunnel? remember the DSl is probably reducing the MTU size due to the overhead with DSL. typically 1492 would be the typical MTU for DSL. What does your DSL have configured ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors