RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS

Showing results for 
Show  only  | Search instead for 
Did you mean: 

RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS

L2 Linker

Hi All,


I have an issue about sip/rtp traffic. Endpoints are using a calling application that used sip protocol . We have also enabled fragment feature in zone protection setting.I investigate this issue and when endpoint make calling, zone protection drops rtp packets because they are fragmented.

Could you inform me is there another solution advice without disabling fragment feature?


Thanks for ur interested


Cyber Elite
Cyber Elite

hi @skucukgul


you could investigate why there is fragemting: you may need to change the MTU and/or enable and tweak TCP MSS on the interfaces to decrease the paymload and prevent fragmentation

Tom Piens
PANgurus - (co)managed services and consultancy

hi @reaper,


firstly thanks for your advice. 

does changing tcp mss payload amount affect to other running thing? And also which amount I should adjust? default amount is 40 as I know.



adjustiing the TCP MSS will impact all traffic (that uses mss in it's header)


there are several tools you could give a try to measure the path MTU to determine the lowest MTU along the path, and then use the mss adjust to lower the mss to match the mtu with the most optimal setting (or give the default a trry)

Tom Piens
PANgurus - (co)managed services and consultancy

L5 Sessionator

Further to reapers suggestions. You could create subinterface on the firewall with a different zone and zone protection profile attached?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!