cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
899
Views
0
Helpful
1
Replies

ASA does not allow ESP fragments to go in outside interface

spapageorgiou
Level 1
Level 1

Hi all,

 

I'm running an ASA with 9.8(2) and I have a IPSEC tunnel with another device. The other device (pfsense) fragments ESP packets in order to fit the MTU, but the ASA does not seem to allow ESP fragments to go in, does not reassemble them and of course I can't see the decapsulated ESP payload to reach the endhost. I have opened the firewall to allow everything.

 

The question is how can i configure the ASA to do reassembly, as it should be and forward the payload to the endhost. 

 

Thanx,

Sp

PS: I know all about PMTU and MSS, but it does not apply in my case, so I would like to reassemble the packets.

 

1 Reply 1

Hi,

just cool suggestion. can you try setting same MTU or fragment thresholds on both side to same value? :)
Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB
Review Cisco Networking for a $25 gift card