Feature Overview
When a packet is nearly the size of the maximum transmission unit (MTU) of the outbound link of the
encrypting router, and it is encapsulated with IPSec headers, it is likely to exceed the MTU of the
outbound link.
This causes packet fragmentation after encryption, which makes the decrypting router reassemble
in the process path. Pre-fragmentation for IPSec VPNs increases the decrypting router’s performance
by enabling it to operate in the high performance CEF path instead of the process path.
Pre-fragmentation for IPSec VPNs enables an encrypting router to pre-determine the encapsulated
packet size from information available in transform sets, which are configured as part of the
IPSec security association (SA). If it is pre-determined that the packet will exceed the MTU of the
output interface, the packet is fragmented before encryption.
This avoids process level reassembly before decryption and helps improve decryption performance and
overall IPSec traffic throughput.
Benefits
Increased Performance
Delivers encryption throughput at maximum encryption hardware accelerator speeds.
This performance increase is for near MTU sized packets.
Uniform Fragmentation
Packets are fragmented into equally sized units to prevent further downstream fragmentation.
Restrictions
Take the following information into consideration before this feature is configured:
Pre-fragmentation for IPSec VPNs is on by default.
Pre-fragmentation for IPSec VPNs operates in IPSec Tunnel mode and IPSec tunnel mode with GRE,
but not with IPSec transport mode.
Pre-fragmentation for IPSec VPNs configured on the decrypting router in a unidirectional traffic scenario
does not improve the performance or change the behavior of either of the peers.
Pre-fragmentation for IPSec VPNs occurs before the transform is applied if compression is turned
on for outgoing packets.
Pre-fragmentation for IPSec VPNs functionality depends on the egress interface crypto ipsec df-bit
configuration and the incoming packet “do not fragment” (DF) bit state. See Table .
You may want use the clear setting for the DF bit when encapsulating tunnel mode IPSec traffic
so you can send packets larger than the available MTU size or if you do not know what the available
MTU size is.
Comments
(There are currently no comments for this post.)