<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show vpn flow: Should &amp;quot;tunnel mtu&amp;quot; be renamed to &amp;quot;suggested tunel mtu&amp;quot;? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12018#M8815</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming the answer to (6) was yes, I dropped the interface MTU down to 1400 and my VPN bandwidth improved, certainly due to the reduced number of fragmented packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is the PAN-OS going through the trouble of computing an ideal MTU but not actually applying it to an interface so that it can participate in PMTUD?&amp;nbsp; What am I not getting?&amp;nbsp; Arg!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Sep 2014 17:50:43 GMT</pubDate>
    <dc:creator>cstech</dc:creator>
    <dc:date>2014-09-05T17:50:43Z</dc:date>
    <item>
      <title>show vpn flow: Should "tunnel mtu" be renamed to "suggested tunel mtu"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12015#M8812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you answer these questions regarding the &lt;STRONG&gt;tunel mtu&lt;/STRONG&gt; that appears in the output below?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;cstankevitz@PA-500-Local&amp;gt; show vpn flow tunnel-id 27&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;tunnel&amp;nbsp; Sterling&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; id:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gateway id:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; local ip:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 164.67.80.124&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; peer ip:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53.103.78.197&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inner interface:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tunnel.1 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outer interface:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ethernet1/5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; session:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20027&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tunnel mtu:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1428&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Who/what computed this MTU?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Did the thing that computed this MTU consider the encryption parameters I am using for the tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Why does this MTU value not participate in PMTUD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. (Same question as 3) Why does the MTU listed above not appear in a tracepath?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. (Same question as 3) Why does the MTU listed above not appear in a "show routing fib"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6. Am I expected to copy the MTU value listed above and paste it as the MTU value for the tunnel interface, overriding the default of 1500?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7. If the answer to (6) is "yes" (which I believe it is), then why didn't the PAN just do it for me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8. Why would PAN confusingly give a tunnel interface two MTUs:the real MTU on the interface that participates in ICMP and another "fake" MTU that displayed above that does not participate in ICMP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9. (Same question as &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Should the label "tunnel mtu" that appears in the output of "show vpn flow tunnel-id" be renamed to "suggested tunnel mtu"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 03:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12015#M8812</guid>
      <dc:creator>cstech</dc:creator>
      <dc:date>2014-09-04T03:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: show vpn flow: Should "tunnel mtu" be renamed to "suggested tunel mtu"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12016#M8813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ethernet interface, the Max MTU size is 1500 bytes. The ESP protocol header will be placed in the top of the IP header.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP header would be 20 Bytes, hence the original data+ EST header size can be max (1500-20&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;=1480 Bytes.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ESP header can be 52 bytes, including below mentioned option field:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ESP header&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;--------------------------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Parameters Index =&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;32 bits)&lt;/STRONG&gt; Arbitrary value used (together with the destination IP address) to identify the security association of the receiving party.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sequence Number (32 bits)&lt;/STRONG&gt; =A monotonically increasing sequence number (incremented by 1 for every packet sent) to protect against replay attacks. There is a separate counter kept for every security association.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Padding (0-255 octets&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;=&lt;/STRONG&gt; Padding for encryption, to extend the payload data to a size that fits the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;encryption's&lt;/SPAN&gt;&lt;/SPAN&gt; cipher block size, and to align the next field.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Payload data (variable)&lt;/STRONG&gt; =The protected contents of the original IP packet, including any data used to protect the contents (e.g. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;an&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Initialisation&lt;/SPAN&gt;&lt;/SPAN&gt; Vector for the cryptographic algorithm). The type of content that was protected is indicated by the Next Header field&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;=Size of the padding (in octets).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Next Header (8 bits)&lt;/STRONG&gt; =Type of the next header. The value is taken from the list of IP protocol numbers.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Integrity Check Value (multiple of 32 bits)&lt;/STRONG&gt; =Variable length &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;check&lt;/SPAN&gt;&lt;/SPAN&gt; value. It may contain padding to align the field to an 8-octet boundary for IPv6, or a 4-octet boundary for IPv4.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Payload data (variable, max 6 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;byte&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/STRONG&gt; =The protected contents of the original IP packet, including any data used to protect the contents (e.g. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;an&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Initialisation&lt;/SPAN&gt;&lt;/SPAN&gt; Vector for the cryptographic algorithm). The type of content that was protected is indicated by the Next Header field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the actual data can pass through the tunnel without fragmentation will be (1480-52&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;=1428 Bytes.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;The tunnel&amp;nbsp; MTU would not depend&amp;nbsp; on encryption parameter. Because, encryption parameter will be identified by SPI (Security parameter index-&lt;/SPAN&gt;&lt;SPAN style="color: #252525; font-family: sans-serif; font-size: 14px;"&gt;to&lt;/SPAN&gt;&lt;SPAN style="color: #252525; font-family: sans-serif; font-size: 14px;"&gt; identify the security association SA&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Path MTU is not being calculated, and any packet more than 1500 Bytes on an ethernet interface will be fragmented&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 10:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12016#M8813</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-04T10:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: show vpn flow: Should "tunnel mtu" be renamed to "suggested tunel mtu"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12017#M8814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help.&amp;nbsp; Would you please consider answering my question #4 and #6 in my original post?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 18:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12017#M8814</guid>
      <dc:creator>cstech</dc:creator>
      <dc:date>2014-09-04T18:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: show vpn flow: Should "tunnel mtu" be renamed to "suggested tunel mtu"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12018#M8815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming the answer to (6) was yes, I dropped the interface MTU down to 1400 and my VPN bandwidth improved, certainly due to the reduced number of fragmented packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is the PAN-OS going through the trouble of computing an ideal MTU but not actually applying it to an interface so that it can participate in PMTUD?&amp;nbsp; What am I not getting?&amp;nbsp; Arg!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 17:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-vpn-flow-should-quot-tunnel-mtu-quot-be-renamed-to-quot/m-p/12018#M8815</guid>
      <dc:creator>cstech</dc:creator>
      <dc:date>2014-09-05T17:50:43Z</dc:date>
    </item>
  </channel>
</rss>

