cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1250
Views
0
Helpful
1
Replies

VPN (IPsec) %IP_VFR-3-OVERLAP_FRAGMENTS issue.

Hi to all.

We have the customer that have some brunches. Each of them connected to their ISP. Central office connected to us. All branches connect to central office via VPN (IPsec). So the issue is in receiving fragmented packets from their ISP. With enabled ip virtual reassembly - all customer traffic transmitt well, but buffer overflow and there is a lot of  overlap fragments (%IP_VFR-3-OVERLAP_FRAGMENTS:), and it's affected to cpu utilization (cpu loads to 99%). I have disabled ip virtual reassembly by issuing ip virtual-reassembly in drop-fragments in command on our uplink interface, cpu utilization is normal, but customer traffic in their tunnel works incorrectly (some packets losts). Can anybody help me with this problem?

 

1 Reply 1

svansteensel
Level 1
Level 1

hi,

You should look at the ip tcp mss size on your interfaces (set it some lower), and maybe setting the threshold for virtual reassembly a bit higher.

regards Sebastian