cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
817
Views
0
Helpful
1
Replies

ASA does not allow ESP fragments to go in outside interface

spapageorgiou
Level 1
Level 1

Hi all,

 

I'm running an ASA with 9.8(2) and I have a IPSEC tunnel with another device. The other device (pfsense) fragments ESP packets in order to fit the MTU, but the ASA does not seem to allow ESP fragments to go in, does not reassemble them and of course I can't see the decapsulated ESP payload to reach the endhost. I have opened the firewall to allow everything.

 

The question is how can i configure the ASA to do reassembly, as it should be and forward the payload to the endhost. 

 

Thanx,

Sp

PS: I know all about PMTU and MSS, but it does not apply in my case, so I would like to reassemble the packets.

 

1 Reply 1

Hi,

just cool suggestion. can you try setting same MTU or fragment thresholds on both side to same value? :)
Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card