VPN Fragmentation

Created by dave. Last edited by dave, 7 years and 13 days ago. Viewed 1,491 times. #2
VPN throughput is slow and you suspect fragmentation.


You can influence the MSS (Maximum Segment Size) passed through the VPN by adding qualifiers to the policies governing traffic flow through the VPN.

You can only do this from the cli at present.


# config firewall policy
# edit <number>
# set tcp-mss-sender 1355
# set tcp-mss-receiver 1355
# next
# end
This is a collection of techical information, much of it learned the hard way. Consider it a lab book or a /info directory. I doubt much of it will be of use to anyone else.

