- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MX - Path MTU under 1500 and AutoVPN
Hi ,
Does anyone have a path MTU lower than 1500 on their WAN and using AutoVPN ? ( Eg : GRE tunnels )
How is the MX handling that ? I know for a fact that if you configure PPPoE on the MX , it lowers the MTU to 1492. I'm just curious about other scenarios.
Will the MX notice that the path MTU is lower than 1500 ? Will it magicly lower it's MTU ?
I'm aware that you can call support to lower the MTU. I'm wondering what kind of setup / issues you guys have encountered.
Cheers ,
- Labels:
-
Auto VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No the mx itself won't lower mtu of the wan by itself. And you could experience fragmentation and performance issues if you wont call support to lower mtu. If the mtu is lowered then all autovpn tunnels will adjust
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AutoVPN performs PMTUD across the entire topology, and will maintain a consistent one across every hop based on the lowest detected value.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Alex for the reply.
Let's say I have this setup :
Site A : 1500
Site B : 1400
Hub C : 1500
Are you implying that every MX on that AutoVPN domain ( the same org ) will lower his MTU to 1400 ? Please note that this is a hub / spoke design AND meshing is disabled.
I coudln't find any documentation about Meraki and PMTUD/MTU
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That is correct.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Okay , sorry I have a hard time grasping that subjet.
50% of my sites are on HUB C , and 50% are on HUB F
Can you confirm the behavior ?
Site A : 1500 -> 1400
Site B : 1400 -> 1400
HUB C : 1500 -> 1400
Site 😧 1500 -> 1500
Site E: 1500 -> 1500
HUB F: 1500 -> 1500
or
( everyone gets choked to 1400 )
Site A : 1500 -> 1400
Site B : 1400 -> 1400
HUB C : 1500 -> 1400
Site 😧 1500 -> 1400
Site E: 1500 -> 1400
HUB F: 1500 -> 1400
If you misconfigure a site to a ultra low MTU , it could easily kill performance over your whole org ? That doesn't seem nice at all.
Thanks ,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, that's still correct.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Alex, thank you for your replies!
Related to the MTU change on MX, please provide answers to the following questions
1. Afther the MTU change on MX, is a reboot needed for the new value to apply?
2. Supposing that no reboot is needed after the MTU change and that AutoVPN was already up before the MTU change - does AutoVPN automatically renegociate after the MTU change? or is needed a manual intervention (deactivate&reactivate the AutoVPN) in order to apply the new value to the AutoVPN?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, that‘s the point about PMTU 😇 Regarding your example, I bet users wouldn‘t even notice.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In a perfect world indeed ! But that's not often the case sadly.
Also , according to my tests, the behavior is way different from what was confirmed by Meraki. I will conclude more tests and comeback with the results.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Both can be possible, depending if hub to hub autovpn communication is on or off
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But just a warning, for non AutoVPN IPsec tunnels, it is a whole mess as the automatic MSS adjustments for lower MTUs is *not* done for these tunnels.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So here are my tests and results.
1 Spoke and Hub with a standard MTU of 1500 and 1 Spoke configured with 1400 :
Spoke A will still continu to use a MTU of 1500. The only effect that Spoke B has on the topology is that the Hub will clamp his own MSS to 1292 so traffic inbound to the hub will be clamped down to 1292 for every single spoke.
Traffic from Spoke A going to the internet ( in a split tunnel configuration ) will STILL use a MSS of 1460 ( MTU : 1500 )
My second test was to introduce a lower MTU in the path of AutoVPN. The only way that I was capable of doing so was to plug Spoke A into MX B ( which was no longer path of the AutoVPN domain ). The MSS advertised by both the Spoke A and HUB were still showing 1392 , which is not possible without fragmentation since the path MTU contains a hop with a lower MTU.
Yes ICMP fragmentation needed messages were flowing quite frequently. But I still think that I will have to lower the MTU on every single spoke instead of relying on PMTUD / icmp fragmentation needed packets.
TL;DR : Setting the MTU on the Spoke to a desired MTU seems the easiest way to account for a known Path MTU that is lower than 1500 ( eg : GRE ). However , relying on Meraki's Support to do it in the backend and loosing vision about that setting ( because it's a backend option ) worries me a lot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version of MX / MG are you running ? And what is the MTU that seems to be used ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MX = 17.10.2
MG = 1.11
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Note that the MG21 is having issues (some firmware near future should fix this though)..
MTU size is default 1280 on a MG21.
Call support for a patch they can run. So the MG21 will start to use MTU1500.