Hi everybody! Just a short question. A customer is asking us if it is possible to change the size of the mtu packets to 1500 in a gre tunnel. As far as I know, there's an overhead at the beginning of these packets depending the type of encryption used, so it wouldn't be possible to do this. Am I right?
Thanks in advance.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Exactly!
Apparently the FG even does a sanity check for you :).
GRE over IPv4 has an overhead of IPv4 (20 bytes) and GRE (4 bytes). Makes a maximum tunnel MTU of 1476.
MTU gets even smaller if over you are tunneling over an IPSEC tunnel.
Anyone please?
Depends on the underlying interface.
But most likely it's <=1500. So then 1500 is too big for the GRE Tunnel.
Thanks for you answer! When we try to set the size to 1500, we get this error message:
FORTI # set mtu 1500
MTU size not valid. Should be in the range of 68 - 1476.
node_check_object fail! for mtu 1500
value parse error before '1500'
Command fail. Return code -2
So in fact, you can't configure it to 1500 because it adds an overhead to these packets?
Exactly!
Apparently the FG even does a sanity check for you :).
GRE over IPv4 has an overhead of IPv4 (20 bytes) and GRE (4 bytes). Makes a maximum tunnel MTU of 1476.
MTU gets even smaller if over you are tunneling over an IPSEC tunnel.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.