Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

IPsec packet fragmentation enhancements

More Information:

IPsec packet fragmentation enhancements

In packets that are transmitted through static and dynamic endpoint IPsec tunnels, you can enable the value set in the Don't Fragment (DF) bit of the packet entering the tunnel to be copied only to the outer header of the IPsec packet and to not cause any modification to the DF bit in the inner header of the IPsec packet. To copy the DF bit value to only the outer header and not modify the inner header, use the copy-dont-fragment-bit statement at the [edit services ipsec-vpn rule rule-name term term-name then] hierarchy level for static tunnels and at the [edit services service-set service-set-name ipsec-vpn-options] hierarchy level for dynamic endpoints. To configure the DF bit in only the outer header of the IPsec packet and to leave the inner header unmodified, include the set-dont-fragment-bit statement at the [edit services ipsec-vpn rule rule-name term term-name then] hierarchy level for static tunnels and at the [edit services service-set service-set-name ipsec-vpn-options] hierarchy level for dynamic endpoints.
Product / Application Software Introduced Release
MX5 Junos OS 14.1R1
MX10 Junos OS 14.1R1
MX40 Junos OS 14.1R1
MX80 Junos OS 14.1R1
MX104 Junos OS 14.1R1
MX240 Junos OS 14.1R1
MX480 Junos OS 14.1R1
MX960 Junos OS 14.1R1
MX2008 Junos OS 15.1F7
MX2010 Junos OS 14.1R1
MX2020 Junos OS 14.1R1