Networking-Blog

My WordPress Blog

PIX/ASA 7.x and IOS: VPN Fragmentation

fragmentation-2.gif

On Cisco Security Appliances, use a capture filter.

access-list outside_test permit tcp any host 172.22.1.1 eq 80

Note: When you leave the source as any, it allows the administrator to
monitor any network address translations (NAT).

access-list outside_test permit tcp host 172.22.1.1 eq 80 any

Note: When you reverse the source and destination information,
it allows return traffic to be captured
.

capture outside_interface access-list outside_test interface outside

The user needs to initiate a new session with application X.
After the user has initiated a new application X session,
the ASA administrator needs to issue the show capture outside_interface command.

1. MTU Change on the Router:

Note that if you manually set the MTU on the device, it tells the device, which acts as a VPN gateway,
to fragment received packets before it protects and sends them across the tunnel.

Warning: If you change the MTU size on any device interface, it causes all tunnels terminated on that
interface to be torn down and rebuilt.

On Cisco routers, use the ip mtu command to adjust the MTU size on the interface where the
VPN is terminated:

interface fa0
ip mtu MTU_size_in_bytes

2. MTU Change on the ASA/PIX :

On ASA/PIX devices, use the mtu command to adjust the MTU size in global config mode.
By default, the MTU is set to 1500. For example, if you had an interface on your security appliance
that was named Outside (where the VPN is terminated), and you determined that you wanted to use
1380 as the fragment size, use this command :

(config)# mtu Outside 1380

Method 2 : TCP Maximum Segment Size
The TCP maximum segment size can solve issues with fragmentation
.
Note: This feature only works with TCP; other IP protocols have to use another solution
to solve IP fragmentation problems. Even if you set the ip mtu on the router, it does not affect
what the two end hosts negotiate within the TCP three-way handshake with TCP MSS
.

3. MSS Change on the Router :

Fragmentation occurs with TCP traffic because TCP traffic is normally used to transport large amounts
of data. TCP supports a feature called TCP maximum segment size (MSS) that allows the two devices to
negotiate a suitable size for TCP traffic.
!
MSS value
is configured statically on each device and represents the buffer size to use for an expected
packet. When two devices establish TCP connections they compare the local MSS value with the
local MTU value within the three-way handshake
; whichever is lower is sent to the remote peer.
The two peers then use the lower of the two exchanged values.

In order to configure this feature, do this

interface fa0
ip tcp adjust-mss MTU_size_in_bytes

4. MSS Change on the ASA/PIX :

In order to ensure that the maximum TCP segment size does not exceed the value you set and that
the maximum is not less than a specified size, use the sysopt connection command in global config mode.
The default maximum value is 1380 bytes. The minimum feature is disabled by default (set to 0).
In order to change the default maximum MSS limit
, do this:

sysopt connection tcp-mss MSS_size_in_bytes

Note
: If you set the maximum size to be greater than 1380, packets can become fragmented,
dependent upon the MTU size (which is 1500 by default). Large numbers of fragments can impact
the performance of the security appliance when it uses the Frag Guard feature
.

If you set the minimum size, it prevents the TCP server from sending many small TCP data
packets to the client and impacting the performance of the server and the network
.

In order to change the minimum MSS limit, do this :

sysopt connection tcp-mss minimum MSS_size_in_bytes

Use the set ip df command to clear the DF bit and allow the packet to be fragmented and sent.
Fragmentation
can slow the speed of packet forwarding on the network, but access lists can be used
to limit the number of packets on which the DF bit is cleared
.

Clear the DF bit in the IP header that the source placed there or manually adjust the TCP MSS size.
In order to clear the DF bit, an intermediate router has to change the value from 1 to 0.
Normally this is done by a router in your network before the packet leaves the network.

********************************************************************

This is a simple code configuration that does this on an IOS-based router :

access-list 199 permit tcp any any
!
route-map route_map_name permit seq#
match ip address name 199
set ip df 0

!
interface fa0
ip policy route-map route_map_name

*******************************************************************

The DF bit with IPSec tunnels feature lets you specify whether the security appliance can
clear, set, or copy the Don’t Fragment (DF) bit
from the encapsulated header.
The DF bit within the IP header determines whether a device is allowed to fragment a packet.

On Cisco Router “crypto ipsec df-bit”
On Pix Router “crypto ipsec df-bit clear-df outside“

When you encapsulate tunnel mode IPSec traffic, use the clear-df setting for the DF bit.
This setting lets the device send packets larger than the available MTU size
.
Also this setting is appropriate if you do not know the available MTU size
.

After the appropriate maximum segment size is achieved, adjust it appropriately for the devices in use :

On the PIX Firewall :
sysopt connection tcpmss 1300

On the router :
ip tcp adjust-mss 1300

Cisco IPSEC Pre-fragmentation VPN’s

Feature Overview

When a packet is nearly the size of the maximum transmission unit (MTU) of the outbound link of the
encrypting router, and it is encapsulated with IPSec headers, it is likely to exceed the
MTU of the
outbound link.

This causes packet fragmentation after encryption, which makes the decrypting router reassemble
in the process path.
Pre-fragmentation for IPSec VPNs increases the decrypting router’s performance
by enabling it to operate in the high performance CEF path instead of the process path.

Pre-fragmentation for IPSec VPNs enables an encrypting router to pre-determine the encapsulated
packet size
from information available in transform sets, which are configured as part of the
IPSec security association (SA). If it is pre-determined that the packet will exceed the MTU of the
output interface, the packet is fragmented before encryption.

This avoids process level reassembly before decryption and helps improve decryption performance and
overall IPSec traffic throughput
.

Benefits

Increased Performance
Delivers encryption throughput at maximum encryption hardware accelerator speeds.
This performance increase is for near MTU sized packets.

Uniform Fragmentation
Packets are fragmented into equally sized units to prevent further downstream fragmentation.

Restrictions

Take the following information into consideration before this feature is configured:

Pre-fragmentation for IPSec VPNs is on by default.
Pre-fragmentation for IPSec VPNs operates in IPSec Tunnel mode and IPSec tunnel mode with GRE,
but not with IPSec transport mode.

Pre-fragmentation for IPSec VPNs configured on the decrypting router in a unidirectional traffic scenario
does not improve the performance or change the behavior of either of the peers.
Pre-fragmentation for IPSec VPNs occurs before the transform is applied if compression is turned
on for outgoing packets
.

Pre-fragmentation for IPSec VPNs functionality depends on the egress interface crypto ipsec df-bit
configuration and the incoming packet “do not fragment” (DF) bit state. See Table .

You may want use the clear setting for the DF bit when encapsulating tunnel mode IPSec traffic
so you can send packets larger than the available MTU size or if you do not know what the available
MTU size
is.

clear Specifies that the outer IP header will have the DF bit cleared and that the router may fragment the packet to add
the IPSec encapsulation.
set Specifies that the outer IP header will have the DF bit set; however, the router may fragment the packet if the
original packet had the DF bit cleared
.
copy Specifies that the router will look in the original packet for the outer DF bit setting.
Table 1 Pre-fragmentation For Ipsec VPNs Dependencies

Enabled crypto ipsec df-bit clear 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit clear 1 Fragmentation occurs before encryption.
Disabled crypto ipsec df-bit clear 0 Fragmentation occurs after encryption and packets are reassembled
before decryption
.
Disabled crypto ipsec df-bit clear 1 Fragmentation occurs after encryption and packets are reassembled before decryption.
Enabled crypto ipsec df-bit set 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit set 1 Packets are dropped.
Disabled crypto ipsec df-bit set 0 Fragmentation occurs after encryption and packets are reassembled before decryption.
Disabled crypto ipsec df-bit set 1 Packets are dropped.
Enabled crypto ipsec df-bit copy 0 Fragmentation occurs before encryption.
Enabled crypto ipsec df-bit copy 1 Packets are dropped.
Disabled crypto ipsec df-bit copy 0 Fragmentation occurs after encryption and packets are reassembled before decryption.
Disabled crypto ipsec df-bit copy 1 Packets are dropped.