Friday, February 1, 2019

Suggestions on dealing with fragmentation over the WAN.

So I'm looking just for some more ideas to brainstorm with intermittent issues we have. I've got a bunch of sites coming back to our data center over IPSEC tunnels. Now due to some restrictions put on us and the ipsec devices we're using, it doesn't appear like we are able to get PMTUD working.

Most sites have a firewall we control, where we've been setting the WAN interface MTU down, because in the past we've had some sites lose functionality. However, it was set a while ago by people who aren't here anymore, and i'm to determine better ways of doing things, as some sites have mtu set down to like 1100.

Now I have the option of simply grabbing a packet capture for wireshark. That is a great tool, but if i'm being honest with my ability, it's not always very clear cut in my eyes. That may be mostly on myself.

Do people on here have suggestions of maybe certain tools to give a try with or maybe even wireshark is the option and you have suggestions of a good way I can use it/filter it.



No comments:

Post a Comment