I have enabled pmtu-discovery as per instructions from this topic Dynamic MTU Configuration in SD-WAN Deplo... - Fortinet Community but MTU on the GRE tunnel remains 1476. I want it to be 1356 for this state when ipsec is off.
one side of that mikrotik - fortigate link is discarding ldap traffic so domain users are unable to log into their computers because of problem in communication between computers and domain controllers... ldap traffic from windows 11 clients to domain controller on port tcp88 and vice-versa has DF bit set and traffic may not be fragmented..
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @netops-1 ,
- You can use following commands:
config sys interface
edit <interface-name>
set mtu-override enable
set mtu <mtu-value>
next
end
Reference article:
hello,
those commands are not available on GRE tunnel interface
Hi netops
From my personal deduction, GRE is still possible on FortiOS (but IPsec is recommended) just for compatibility with old fashion networks. This is probably the reason for which it doesn't have as many customization possibilities as IPsec interface.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.