<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216752#M62759</link>
    <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firstly thanks for your advice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;does changing tcp mss payload&amp;nbsp;amount affect to other running thing? And also which amount I should adjust? default amount is 40 as I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jun 2018 22:22:01 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2018-06-05T22:22:01Z</dc:date>
    <item>
      <title>RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216620#M62735</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an issue about sip/rtp traffic. Endpoints are using a calling application that used sip protocol . We have also enabled fragment feature in zone protection setting.I investigate this issue and when endpoint make calling, zone protection drops rtp packets because they are fragmented.&lt;/P&gt;&lt;P&gt;Could you inform me is there another solution advice without disabling fragment feature?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for ur interested&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 09:29:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216620#M62735</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-06-05T09:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216648#M62737</link>
      <description>&lt;P&gt;hi @Retired Member&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could investigate why there is fragemting: you may need to change the MTU and/or enable and tweak TCP MSS on the interfaces to decrease the paymload and prevent fragmentation&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 13:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216648#M62737</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-05T13:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216752#M62759</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firstly thanks for your advice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;does changing tcp mss payload&amp;nbsp;amount affect to other running thing? And also which amount I should adjust? default amount is 40 as I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 22:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216752#M62759</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-06-05T22:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216789#M62762</link>
      <description>&lt;P&gt;adjustiing the TCP MSS will impact all traffic (that uses mss in it's header)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are several tools you could give a try to measure the path MTU to determine the lowest MTU along the path, and then use the mss adjust to lower the mss to match the mtu with the most optimal setting (or give the default a trry)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 07:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216789#M62762</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-06T07:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216841#M62770</link>
      <description>&lt;P&gt;Further to reapers suggestions. You could create subinterface on the firewall with a different zone and zone protection profile attached?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 13:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216841#M62770</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-06T13:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216996#M62802</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As recent informs, dropping calling is not because of RTP packets. Amount of last sip communication packet exceeds interface MTU size and therefore packet&amp;nbsp;will be sent by fragment by dividing. In this stage we have to increase interface MTU size instead of decreaing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But this time increasing MTU size will impact some processes. I'm trying to have communication packet decreased or create new zone for this traffic. I will let you keep posted soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 14:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rtp-fragment-packet-flowing-is-not-allowed-when-fragment-enabled/m-p/216996#M62802</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-06-07T14:11:25Z</dc:date>
    </item>
  </channel>
</rss>

