Cisco IPSEC Pre-fragmentation VPN’s

Feature Overview

When a packet is nearly the size of the maximum transmission unit (MTU) of the outbound link of the
encrypting router, and it is encapsulated with IPSec headers, it is likely to exceed the
MTU of the
outbound link.

This causes packet fragmentation after encryption, which makes the decrypting router reassemble
in the process path.
Pre-fragmentation for IPSec VPNs increases the decrypting router’s performance
by enabling it to operate in the high performance CEF path instead of the process path.

Pre-fragmentation for IPSec VPNs enables an encrypting router to pre-determine the encapsulated
packet size
from information available in transform sets, which are configured as part of the
IPSec security association (SA). If it is pre-determined that the packet will exceed the MTU of the
output interface, the packet is fragmented before encryption.

This avoids process level reassembly before decryption and helps improve decryption performance and
overall IPSec traffic throughput
.

Benefits

Increased Performance
Delivers encryption throughput at maximum encryption hardware accelerator speeds.
This performance increase is for near MTU sized packets.

Uniform Fragmentation
Packets are fragmented into equally sized units to prevent further downstream fragmentation.

Restrictions

Take the following information into consideration before this feature is configured:

Pre-fragmentation for IPSec VPNs is on by default.
Pre-fragmentation for IPSec VPNs operates in IPSec Tunnel mode and IPSec tunnel mode with GRE,
but not with IPSec transport mode.

Pre-fragmentation for IPSec VPNs configured on the decrypting router in a unidirectional traffic scenario
does not improve the performance or change the behavior of either of the peers.
Pre-fragmentation for IPSec VPNs occurs before the transform is applied if compression is turned
on for outgoing packets
.

Pre-fragmentation for IPSec VPNs functionality depends on the egress interface crypto ipsec df-bit
configuration and the incoming packet “do not fragment” (DF) bit state. See Table .

You may want use the clear setting for the DF bit when encapsulating tunnel mode IPSec traffic
so you can send packets larger than the available MTU size or if you do not know what the available
MTU size
is.

clear Specifies that the outer IP header will have the DF bit cleared and that the router may fragment the packet to add
the IPSec encapsulation.
set Specifies that the outer IP header will have the DF bit set; however, the router may fragment the packet if the
original packet had the DF bit cleared
.
copy Specifies that the router will look in the original packet for the outer DF bit setting.
Table 1 Pre-fragmentation For Ipsec VPNs Dependencies

Enabled crypto ipsec df-bit clear 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit clear 1 Fragmentation occurs before encryption.
Disabled crypto ipsec df-bit clear 0 Fragmentation occurs after encryption and packets are reassembled
before decryption
.
Disabled crypto ipsec df-bit clear 1 Fragmentation occurs after encryption and packets are reassembled before decryption.
Enabled crypto ipsec df-bit set 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit set 1 Packets are dropped.
Disabled crypto ipsec df-bit set 0 Fragmentation occurs after encryption and packets are reassembled before decryption.
Disabled crypto ipsec df-bit set 1 Packets are dropped.
Enabled crypto ipsec df-bit copy 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit copy 1 Packets are dropped.
Disabled crypto ipsec df-bit copy 0 Fragmentation occurs after encryption and packets are reassembled before decryption.
Disabled crypto ipsec df-bit copy 1 Packets are dropped.