cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
974
Views
0
Helpful
1
Replies

VPN (IPsec) %IP_VFR-3-OVERLAP_FRAGMENTS issue.

Hi to all.

We have the customer that have some brunches. Each of them connected to their ISP. Central office connected to us. All branches connect to central office via VPN (IPsec). So the issue is in receiving fragmented packets from their ISP. With enabled ip virtual reassembly - all customer traffic transmitt well, but buffer overflow and there is a lot of  overlap fragments (%IP_VFR-3-OVERLAP_FRAGMENTS:), and it's affected to cpu utilization (cpu loads to 99%). I have disabled ip virtual reassembly by issuing ip virtual-reassembly in drop-fragments in command on our uplink interface, cpu utilization is normal, but customer traffic in their tunnel works incorrectly (some packets losts). Can anybody help me with this problem?

 

1 Reply 1

svansteensel
Level 1
Level 1

hi,

You should look at the ip tcp mss size on your interfaces (set it some lower), and maybe setting the threshold for virtual reassembly a bit higher.

regards Sebastian

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card