Friday, September 11, 2020

IPSEC/UDP fragmentation - fragmenting an existing fragment on the path?

Hi,

Was wondering if someone here is so deep into the theory bits that they could elaborate on practical consequences of fragmenting a payload more than once on the path of the packet. I have a case where I use double tunneling (VPN tunnel inside a VPN tunnel) and was wondering if fragmenting an already existing fragment means it's essentially impossible for the packet to get through or is it just increasingly unlikely?

I had a practical issue that I will probably try to solve by decreasing the size of the packet, but was wondering how this should even work in theory? My own guess would be that the packet might pass, but it's more likely for timers etc to run out before reassembly happens properly, especially with different sets of timers running on different hosts.



No comments:

Post a Comment