PIX/ASA 7.x and IOS: VPN Fragmentation

On Cisco Security Appliances, use a capture filter.
access-list outside_test permit tcp any host 172.22.1.1 eq 80
Note: When you leave the source as any, it allows the administrator to
monitor any network address translations (NAT).
access-list outside_test permit tcp host 172.22.1.1 eq 80 any
Note: When you reverse the source and destination information,
it allows return traffic to be captured.
capture outside_interface access-list outside_test interface outside
The user needs to initiate a new session with application X.
After the user has initiated a new application X session,
the ASA administrator needs to issue the show capture outside_interface command.
1. MTU Change on the Router:
Note that if you manually set the MTU on the device, it tells the device, which acts as a VPN gateway,
to fragment received packets before it protects and sends them across the tunnel.
Warning: If you change the MTU size on any device interface, it causes all tunnels terminated on that
interface to be torn down and rebuilt.
On Cisco routers, use the ip mtu command to adjust the MTU size on the interface where the
VPN is terminated:
interface fa0
ip mtu MTU_size_in_bytes
2. MTU Change on the ASA/PIX :
On ASA/PIX devices, use the mtu command to adjust the MTU size in global config mode.
By default, the MTU is set to 1500. For example, if you had an interface on your security appliance
that was named Outside (where the VPN is terminated), and you determined that you wanted to use
1380 as the fragment size, use this command :
(config)# mtu Outside 1380
Method 2 : TCP Maximum Segment Size
The TCP maximum segment size can solve issues with fragmentation .
Note: This feature only works with TCP; other IP protocols have to use another solution
to solve IP fragmentation problems. Even if you set the ip mtu on the router, it does not affect
what the two end hosts negotiate within the TCP three-way handshake with TCP MSS .
3. MSS Change on the Router :
Fragmentation occurs with TCP traffic because TCP traffic is normally used to transport large amounts
of data. TCP supports a feature called TCP maximum segment size (MSS) that allows the two devices to
negotiate a suitable size for TCP traffic.
!
MSS value is configured statically on each device and represents the buffer size to use for an expected
packet. When two devices establish TCP connections they compare the local MSS value with the
local MTU value within the three-way handshake; whichever is lower is sent to the remote peer.
The two peers then use the lower of the two exchanged values.
In order to configure this feature, do this
interface fa0
ip tcp adjust-mss MTU_size_in_bytes
4. MSS Change on the ASA/PIX :
In order to ensure that the maximum TCP segment size does not exceed the value you set and that
the maximum is not less than a specified size, use the sysopt connection command in global config mode.
The default maximum value is 1380 bytes. The minimum feature is disabled by default (set to 0).
In order to change the default maximum MSS limit , do this:
sysopt connection tcp-mss MSS_size_in_bytes
Note : If you set the maximum size to be greater than 1380, packets can become fragmented,
dependent upon the MTU size (which is 1500 by default). Large numbers of fragments can impact
the performance of the security appliance when it uses the Frag Guard feature.
If you set the minimum size, it prevents the TCP server from sending many small TCP data
packets to the client and impacting the performance of the server and the network.
In order to change the minimum MSS limit, do this :
sysopt connection tcp-mss minimum MSS_size_in_bytes
Use the set ip df command to clear the DF bit and allow the packet to be fragmented and sent.
Fragmentation can slow the speed of packet forwarding on the network, but access lists can be used
to limit the number of packets on which the DF bit is cleared.
Clear the DF bit in the IP header that the source placed there or manually adjust the TCP MSS size.
In order to clear the DF bit, an intermediate router has to change the value from 1 to 0.
Normally this is done by a router in your network before the packet leaves the network.
********************************************************************
This is a simple code configuration that does this on an IOS-based router :
access-list 199 permit tcp any any
!
route-map route_map_name permit seq#
match ip address name 199
set ip df 0
!
interface fa0
ip policy route-map route_map_name
*******************************************************************
The DF bit with IPSec tunnels feature lets you specify whether the security appliance can
clear, set, or copy the Don’t Fragment (DF) bit from the encapsulated header.
The DF bit within the IP header determines whether a device is allowed to fragment a packet.
On Cisco Router “crypto ipsec df-bit”
On Pix Router “crypto ipsec df-bit clear-df outside“
When you encapsulate tunnel mode IPSec traffic, use the clear-df setting for the DF bit.
This setting lets the device send packets larger than the available MTU size .
Also this setting is appropriate if you do not know the available MTU size .
After the appropriate maximum segment size is achieved, adjust it appropriately for the devices in use :
On the PIX Firewall :
sysopt connection tcpmss 1300
On the router :
ip tcp adjust-mss 1300