Thursday, March 11, 2021

Another MTU question

The more I think I understand MTU, the more I wonder if I truly understand.

Simple problem I hope, but on a physical link between a router and a firewall with IPSec over the top (via Azure vNet) I have the following -

  1. Mismatched MTU between Physical interfaces 1460 and 1500
  2. Mismatched MTU between Tunnel interfaces 1500 & 1424

I have taken a packet capture and I see encrypted traffic, with the highest frame length of 1434.

Now, I have bad performance over this link, but I can't see the fragmentation in the packet capture. Is wireshark putting them back together? Is mismatched MTU bad, I think so. I even see the tunnel MTU higher than the interface MTU so this would also cause fragmentation?

Brad



No comments:

Post a Comment