Firewall accepts frames larger than the configured MTU of the interface

Firewall accepts frames larger than the configured MTU of the interface

13660
Created On 09/26/18 20:46 PM - Last Modified 06/09/23 07:53 AM


Resolution


The Maximum Transmission Units (MTU) are actually only enforced when packets leave the Palo Alto Networks firewall, with the MTU of the egress interface being applied.

 

When receiving frames, the MRU (Maximum Receiving Units) is applied, which is higher than the average MTU (or even higher if jumbo frames are enabled).

 

The MRU for all interfaces can be viewed by executing the following command:

show system state filter-pretty sw.dev.runtime.ifmon.port-states | match mru

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5cCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language