<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Path MTU Discovery Broken on FTDv with PPPoE Interface (6.6 &amp;amp; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/5266872#M1119846</link>
    <description>&lt;P&gt;To your knowledge was this ever fixed in an update/ newer release or is the fix really simply an individual needs done manually?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Mar 2025 17:53:43 GMT</pubDate>
    <dc:creator>TheGoob</dc:creator>
    <dc:date>2025-03-03T17:53:43Z</dc:date>
    <item>
      <title>Path MTU Discovery Broken on FTDv with PPPoE Interface (6.6 &amp; 7.0)</title>
      <link>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/4506731#M1085290</link>
      <description>&lt;P&gt;I am moving a PPPOE-based internet connection from an FTDv running 6.4.0.8-28 on ESXi to a 6.6.5-13 FTDv running on the same ESXi host. The only other difference is the old was managed by an FMC, the new is managed locally (FDM).&lt;/P&gt;&lt;P&gt;On the original FTD I never changed the outside interface MTU (it's at 1500). On the new FTD I tried lowering the MTU to 1452.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the old connection, Path MTU Discovery works.&lt;/P&gt;&lt;P&gt;Verification: I cannot ping out to the internet with a full 1500-byte packet with the DF bit set, but I have no connectivity issues (standard web browsing) because (I assume) PMTUD works and lowers my PC's transmission units to stay under what the pppoe connection supports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I cut over to the new connection (FTDv 6.6) there are many websites that don't work. Looking at the ASP drops on the FTDv I see it dropping packets with errors stating fragmentation required but df-bit set.&lt;/P&gt;&lt;P&gt;To confirm the issue I hard-coded my PC MTU to 1450 and I have no problem browsing websites. As soon as I set it to 1500 I have problems. It sounds to me like PMTUD is broken when traffic flows through the new FTD.&lt;/P&gt;&lt;P&gt;I also tried a 7.0 FTDv with the same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the new connection I did a packet capture on my PC. I can see packets leaving my PC&amp;nbsp;@ 1514 bytes. I see ICMP Destination unreachable (Fragmentation needed) packets from the firewall.&lt;/P&gt;&lt;P&gt;As soon as I move the connection to the old firewall, no change to the PC, I run a capture and never see a single ICMP Dest Unreachable and the max size I ever see leave the PC is 1434 bytes.&lt;/P&gt;&lt;P&gt;I don't get what's happening, any thoughts?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 18:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/4506731#M1085290</guid>
      <dc:creator>AJ Cruz</dc:creator>
      <dc:date>2021-11-22T18:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Path MTU Discovery Broken on FTDv with PPPoE Interface (6.6 &amp;</title>
      <link>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/4506834#M1085303</link>
      <description>&lt;P&gt;I think I just fixed it. I've been battling this for a couple weeks.&lt;/P&gt;&lt;P&gt;I just noticed the 6.4 FTD has this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sysopt connection tcpmss 1380
sysopt connection tcpmss minimum 0&lt;/PRE&gt;&lt;P&gt;And the 6.6 FTD has this:&lt;/P&gt;&lt;PRE&gt;sysopt connection tcpmss 0
sysopt connection tcpmss minimum 0&lt;/PRE&gt;&lt;P&gt;I created a flexconfig policy on the 6.6 FTD to push&lt;/P&gt;&lt;PRE&gt;sysopt connection tcpmss 1380&lt;/PRE&gt;&lt;P&gt;and it seems to be working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 22:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/4506834#M1085303</guid>
      <dc:creator>AJ Cruz</dc:creator>
      <dc:date>2021-11-22T22:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Path MTU Discovery Broken on FTDv with PPPoE Interface (6.6 &amp;</title>
      <link>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/5266872#M1119846</link>
      <description>&lt;P&gt;To your knowledge was this ever fixed in an update/ newer release or is the fix really simply an individual needs done manually?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 17:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/path-mtu-discovery-broken-on-ftdv-with-pppoe-interface-6-6-amp-7/m-p/5266872#M1119846</guid>
      <dc:creator>TheGoob</dc:creator>
      <dc:date>2025-03-03T17:53:43Z</dc:date>
    </item>
  </channel>
</rss>

