- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-23-2025 07:10 AM
Hi Community,
we are thinking about enabling Jumbo frames globally on PA-5430 firewall that is connected to Nexus and Catalyst.
- Nexus for high performance & storage with MTU 9216.
- Catalyst for all the standard stuff with MTU 1500.
Are there any limitations, drawbacks, concerns by enabling Jumbo frames instead of using standard MTU 1500 (and maybe have 10% bandwidth reduction by not using Jumbo frames) ?
Any experiences are welcome. Thanks a lot.
Best regards,
Henry
05-23-2025 06:59 PM
Hi @henry.engel ,
Jumbo frames must be enabled end-to-end. On the Nexus, that would mean jumbo frames from VM host to VM host or to storage. I have seen jumbo frames significantly speed up vMotion or storage data.
For the campus network (Catalyst), it is generally not needed. Of course, your NGFW Internet should match the MTU of the ISP, which is probably 1500. The biggest issue if you do not enable jumbo frames everywhere is that jumbo packets received on interfaces with normal MTU will be dropped. If you do not enable jumbo frames on the hosts, then they won't take advantage of the larger frames.
Thanks,
Tom
05-29-2025 06:01 AM
@henry.engel wrote:
Hi Community,
we are thinking about enabling Jumbo frames globally on PA-5430 firewall that is connected to Nexus and Catalyst.
- Nexus for high performance & storage with MTU 9216.
- Catalyst for all the standard stuff with MTU 1500.
Are there any limitations, drawbacks, concerns by enabling Jumbo frames instead of using standard MTU 1500 (and maybe have 10% bandwidth reduction by not using Jumbo frames) ?
Any experiences are welcome. Thanks a lot.
Best regards,
Henry
I wouldn't only enable jumbo frames if they're absolutely necessary. I'm not sure about the 5400 series, I'd ask your SE, but on the 5200 series enabling jumbo frames severely limits the firewalls buffer space.
You mentioned Nexus and Catalyst Cisco switches. How do endpoints connected off these network segments communicate though the firewall? If "datacenter" traffic stays on the Nexus side (application & database communication) & just general policy / routing through the firewall into the catalyst environment then I wouldn't enable jumbo frames on the firewall (without talking to your SE.)
If high volume data like servers accessing storage mounts, or interconnected components of an application communicate through the firewall then it would probably be necessary jumbo frames.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!