<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama fragmentation in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542158#M1269</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;If the checkbox for Fragmented traffic is uncheck, does that mean that the fw will not discard fragmented traffic?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Richard_M_3-1684146287887.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50170iC66B450A6B3BB677/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Richard_M_3-1684146287887.png" alt="Richard_M_3-1684146287887.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case where someone says "10.154.74.0/23: We can not send from, or send to,&amp;nbsp; packages bigger than 1472. All ports are defined to 9216 bits. 10.154.74.17 and 10.154.74.34 can be pinged with big packages."&lt;BR /&gt;&lt;BR /&gt;I checked the interface and it has an MTU size off 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Richard_M_2-1684146274804.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50169i9174081DCED343AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Richard_M_2-1684146274804.png" alt="Richard_M_2-1684146274804.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the setup shown, will it mean that the fw allows fragmentation, and will it do so in both directions?&amp;nbsp;&lt;BR /&gt;If it only allows it in one direction, is it possible to allow it in both direction? and if so, how do I do that?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 May 2023 10:49:54 GMT</pubDate>
    <dc:creator>Richard_M</dc:creator>
    <dc:date>2023-05-15T10:49:54Z</dc:date>
    <item>
      <title>Panorama fragmentation</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542158#M1269</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;If the checkbox for Fragmented traffic is uncheck, does that mean that the fw will not discard fragmented traffic?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Richard_M_3-1684146287887.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50170iC66B450A6B3BB677/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Richard_M_3-1684146287887.png" alt="Richard_M_3-1684146287887.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case where someone says "10.154.74.0/23: We can not send from, or send to,&amp;nbsp; packages bigger than 1472. All ports are defined to 9216 bits. 10.154.74.17 and 10.154.74.34 can be pinged with big packages."&lt;BR /&gt;&lt;BR /&gt;I checked the interface and it has an MTU size off 1500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Richard_M_2-1684146274804.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50169i9174081DCED343AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Richard_M_2-1684146274804.png" alt="Richard_M_2-1684146274804.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the setup shown, will it mean that the fw allows fragmentation, and will it do so in both directions?&amp;nbsp;&lt;BR /&gt;If it only allows it in one direction, is it possible to allow it in both direction? and if so, how do I do that?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 10:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542158#M1269</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-05-15T10:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama fragmentation</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542292#M1273</link>
      <description>&lt;P&gt;If it's checked then you will drop all fragmented traffic, so you are correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps you need to enable jumboframes if you haven't done so already?&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 10:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542292#M1273</guid>
      <dc:creator>kat3xx</dc:creator>
      <dc:date>2023-05-16T10:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama fragmentation</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542541#M1276</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289206"&gt;@kat3xx&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thank you for your answer. I checked the jumboframe and it was already enabled.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I got some more info.&lt;BR /&gt;There are two situations. One where it works and one where it don`t work:&lt;BR /&gt;The source is the same but the destionation address is different and is in two differente DC. There exists opening for both secenarios.&lt;BR /&gt;&lt;BR /&gt;Situation 1:&lt;BR /&gt;The src and dst address is in the same DC and the traffic only need to go through one zone and one fw. In this case, everything works as intended.&lt;BR /&gt;&lt;BR /&gt;Situation 2:&lt;BR /&gt;The src and dst address is in two different DC`s and the traffic goes through three zones. In this case the fragmentet traffic is not received at the dst.&lt;BR /&gt;&lt;BR /&gt;From what I can see from the traffic log, the traffic is allowed in both situations, but is there someway to see if fragmented traffic is going through in some way or is it enough to see that the traffic is allowed in the traffic log?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;They also did some ping where should have issued a ping with up to 1472 packets (if you can say it like that) and it went through, but if they issued a ping from 1473 and above it didn`t work. Does this give any sense?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there something else I should check?&lt;BR /&gt;I am not sure if this is a fw issue or not.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 20:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panorama-fragmentation/m-p/542541#M1276</guid>
      <dc:creator>Richard_M</dc:creator>
      <dc:date>2023-05-17T20:21:30Z</dc:date>
    </item>
  </channel>
</rss>

