cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
613
Views
0
Helpful
1
Replies

ipsec and IP fragment

m.baker
Level 1
Level 1

Hi,

I know that if a packet is too large, the Cisco router can fragment some packets (if DF bit not set) before encrypting them and encapsulating them in ipsec.

However, is the actual IPSEC packet sent by the router setting the DF bit in the IP outer IP layer header ? I.e. Can the IPSEC packets themselves be fragmented ?

Thanks

1 Reply 1

m.baker
Level 1
Level 1

ok. found the answer to this one...IPSEC packets from Cisco routers always have the DF bit cleared.