<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MTU problem PA-500 5.0.6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12787#M9368</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please find below a screenshot and verify MTU on both ingress and egress interface of the PAN firewall. Also, could you please check "adjust MSS" option and do a test &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;for TCP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="MTU.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13896_MTU.JPG" style="height: 335px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jun 2014 07:44:03 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-06-12T07:44:03Z</dc:date>
    <item>
      <title>MTU problem PA-500 5.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12786#M9367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a PA-500 5.0.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From inside my network I see an MTU maximum of 1023.&amp;nbsp; From outside through my ISP I see the MTU that I expect of 1492.&amp;nbsp; Traffic through the PA sees an MTU of 1023.&amp;nbsp; I haven't changed the interfaces.&amp;nbsp; Is this possible to fix?&amp;nbsp; Where in the PA config would I look?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;bb33@bb33-vlinux:~&amp;nbsp; 
$ ping -s 995 google.com
PING google.com (74.125.237.96) 995(1023) bytes of data.
1003 bytes from syd01s12-in-f0.1e100.net (74.125.237.96): icmp_req=1 ttl=52 time=29.8 ms
1003 bytes from syd01s12-in-f0.1e100.net (74.125.237.96): icmp_req=2 ttl=52 time=29.6 ms
^C
--- google.com ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 29.673/29.782/29.892/0.204 ms
bb33@bb33-vlinux:~ 1 
$ ping -s 996 google.com
PING google.com (74.125.237.201) 996(1024) bytes of data.
^C
--- google.com ping statistics ---
36 packets transmitted, 0 received, 100% packet loss, time 35253ms

bb33@bb33-vlinux:~ 1 
$

&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2014 07:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12786#M9367</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-12T07:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: MTU problem PA-500 5.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12787#M9368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please find below a screenshot and verify MTU on both ingress and egress interface of the PAN firewall. Also, could you please check "adjust MSS" option and do a test &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;for TCP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="MTU.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13896_MTU.JPG" style="height: 335px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2014 07:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12787#M9368</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-12T07:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: MTU problem PA-500 5.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12788#M9369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you have zone protection on an interface the largest ICMP packet allowed is 1024 - TCP and ICMP header = 995. You can remove the ICMP large packet option in the zone protection profile&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1122"&gt;The Largest ICMP Packet Allowed with Zone Protection Enabled for Large ICMP Packets&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2014 12:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12788#M9369</guid>
      <dc:creator>patmal</dc:creator>
      <dc:date>2014-06-12T12:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: MTU problem PA-500 5.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12789#M9370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;When you have zone protection on an interface the largest ICMP packet allowed is 1024 - TCP and ICMP header = 995. You can remove the ICMP large packet option in the zone protection profile&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought this might be it.&amp;nbsp; It sounds right and has the right numbers but I unticked that option for my internal network and "&lt;EM&gt;ping -s 996 google.com&lt;/EM&gt;" to outside still failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My bad.&amp;nbsp; This is correct, but I had to add it to the egress interface (of course).&amp;nbsp; Now I am seeing a max MTU of 1442 (1470).&amp;nbsp; Not sure why it's not 1464 (1492).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2014 01:33:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mtu-problem-pa-500-5-0-6/m-p/12789#M9370</guid>
      <dc:creator>gmoss</dc:creator>
      <dc:date>2014-06-13T01:33:40Z</dc:date>
    </item>
  </channel>
</rss>

