<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SD-WAN adjust MSS - PAN-OS in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-adjust-mss-pan-os/m-p/563526#M128</link>
    <description>&lt;P&gt;I'd like to understand if Palo Alto SD-WAN automatically changes (or can change) the MSS value in the TCP 3 way handshake.&lt;/P&gt;
&lt;P&gt;SD-WAN checks the underlaying tunnel interfaces on their MTU and applies the minimum MTU to the related SD-WAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When checking an SD-WAN interface you can check the Interface MTU (in the example 1423).&lt;/P&gt;
&lt;P&gt;The "Adjust TCP MSS" is set to &lt;STRONG&gt;no&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to set the&amp;nbsp;Adjust TCP MSS to yes so this value is automatically set to the SD-WAN interface MTU - 40?&lt;/P&gt;
&lt;P&gt;Or tis this already applied by the SD-WAN functionality. (For&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/5-4/prisma-sd-wan-ion-release-notes/prisma-sd-wan-ion-release-5-4/features-introduced-in-prisma-sd-wan-release-5-4/features-introduced-in-prisma-sd-wan-release-5-4-1#id1787E6003UC" target="_self"&gt;Prisma SD-WAN&lt;/A&gt;&amp;nbsp; this was introduced in 5.4.1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Name: sdwan.949, ID: 245&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Operation mode: layer3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Virtual router vr1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Interface MTU 1423&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Interface management profile: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Service configured: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Zone: zone-to-branch, virtual system: vsys1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Adjust TCP MSS: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Ignore IPv4 DF: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Policing: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SD-WAN interface members: tunnel.xx,tunnel.xx&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2023 13:57:52 GMT</pubDate>
    <dc:creator>peter.vandereijk</dc:creator>
    <dc:date>2023-10-30T13:57:52Z</dc:date>
    <item>
      <title>SD-WAN adjust MSS - PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-adjust-mss-pan-os/m-p/563526#M128</link>
      <description>&lt;P&gt;I'd like to understand if Palo Alto SD-WAN automatically changes (or can change) the MSS value in the TCP 3 way handshake.&lt;/P&gt;
&lt;P&gt;SD-WAN checks the underlaying tunnel interfaces on their MTU and applies the minimum MTU to the related SD-WAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When checking an SD-WAN interface you can check the Interface MTU (in the example 1423).&lt;/P&gt;
&lt;P&gt;The "Adjust TCP MSS" is set to &lt;STRONG&gt;no&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to set the&amp;nbsp;Adjust TCP MSS to yes so this value is automatically set to the SD-WAN interface MTU - 40?&lt;/P&gt;
&lt;P&gt;Or tis this already applied by the SD-WAN functionality. (For&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-sd-wan/5-4/prisma-sd-wan-ion-release-notes/prisma-sd-wan-ion-release-5-4/features-introduced-in-prisma-sd-wan-release-5-4/features-introduced-in-prisma-sd-wan-release-5-4-1#id1787E6003UC" target="_self"&gt;Prisma SD-WAN&lt;/A&gt;&amp;nbsp; this was introduced in 5.4.1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Name: sdwan.949, ID: 245&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Operation mode: layer3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Virtual router vr1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Interface MTU 1423&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Interface management profile: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Service configured: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Zone: zone-to-branch, virtual system: vsys1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Adjust TCP MSS: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Ignore IPv4 DF: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Policing: no&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SD-WAN interface members: tunnel.xx,tunnel.xx&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 13:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-adjust-mss-pan-os/m-p/563526#M128</guid>
      <dc:creator>peter.vandereijk</dc:creator>
      <dc:date>2023-10-30T13:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN adjust MSS - PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-adjust-mss-pan-os/m-p/576459#M155</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a followup question for this one..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've read&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/community-blogs/tcp-mss-adjustments-updated-february-2023/ba-p/156881" target="_blank"&gt;https://live.paloaltonetworks.com/t5/community-blogs/tcp-mss-adjustments-updated-february-2023/ba-p/156881&lt;/A&gt;&amp;nbsp;together with all the extra included KB articles.&lt;BR /&gt;&lt;BR /&gt;But it's still unclear to me how I can manualy manipulate the MSS-value of tunnels set up by the SD-WAN pluging.&lt;/P&gt;
&lt;P&gt;The KB states that the MSS is automaticly adjusted by the FW itself, but in my case these are still too high.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;According the KB articles I can change these values in the tunnel-interface. But all these examples are based on IPSec tunnels set up manualy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I change these values of the tunnels generated by the SDWAN-plugin, will I break this feature? Is it overwritten with a next policy push?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be great to change these values in Panorama and push them, but I know the SDWAN pluging doesn't work that way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 14:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-adjust-mss-pan-os/m-p/576459#M155</guid>
      <dc:creator>WtrN06</dc:creator>
      <dc:date>2024-02-07T14:49:45Z</dc:date>
    </item>
  </channel>
</rss>

