09-19-2024 05:58 AM - edited 09-19-2024 06:18 AM
Please refer the below topology,
Client >>> Cisco router >>> Firewall >>> Upstream device >>> server
I have set mtu as 200 in my upstream device and as exepected when client access the server(http) the packets are fragmented.
However when I set tcp-mss(in my case to 55)on my Firewall, I can see it is successfully shared(updated mss) on 3 way handshake, However I can still see client or server is sending MSS more than 55 which is causing fragmentation.
Is it expected?Kindly help
09-19-2024 10:06 AM
what is Firewall you have is it asa?
MHM
09-21-2024 03:32 AM
Hi, no I am using fortigate, even if I use a cisco router with the same settings it is not working
09-21-2024 03:36 AM
Only think make tcp mss not work in both FW and router is you using some kind of RA VPN' so are you use RA VPN?
If you use RA VPN then FW and router not see the tcp handshake and hence can not modify the mss
MHM
09-21-2024 03:39 AM
09-19-2024 10:12 AM
Generally i would not touch on firewall MTU and MSS (until we looking to uplift to jumbo frames)
if you are using as ASA firewall look some guide lines :
Make sure MTU match all over the path for better performance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide