MTU & “DF flag” best practice on GreenNode

FTG_GW # config system interface edit <interface-name> set mtu-override enable set mtu next end
$ ifconfig <interface_name> mtu <mtu_size> uppost-up /sbin/ifconfig <interface_name> mtu <mtu_size>
Payload Size
New IPv4 Header for IPsec
AH Header
Next Header - 1
Payload - 1
Reserved - 2
SPI - 4
Sequence - 4
AH Digest
ESP Header
SPI - 4
Sequence - 4
ESP IV
Original IPv4 Header
Original IPv4 Payload
ESP Trailer
ESP Pad - 2
Pad Length - 1
Next Header - 1
ESP ICV - 32
Total IPsec Packet Size sending out from VM
Payload Size
New IPv4 Header for IPsec
UDP Header (NAT-T)
AH Header
Next Header - 1
Payload - 1
Reserved - 2
SPI - 4
Sequence - 4
AH Digest
ESP Header
SPI - 4
Sequence - 4
ESP IV
Original IPv4 Header
Original IPv4 Payload
ESP Trailer
ESP Pad - 2
Pad Length - 1
Next Header - 1
ESP ICV - 32
Total IPsec Packet Size sending out from VM
Payload Size
New IPv4 Header for IPsec
UDP Header (NAT-T)
AH Header
Next Header - 1
Payload - 1
Reserved - 2
SPI - 4
Sequence - 4
AH Digest
ESP Header
SPI - 4
Sequence - 4
ESP IV
New IPv4 Header for GRE
GRE Header + Tunnel Key
Original IPv4 Header
Original IPv4 Payload
ESP Trailer
ESP Pad - 6
Pad Length - 1
Next Header - 1
ESP ICV - 32
Total IPsec Packet Size sending out from VM
Last updated

