SonicWall VPN says Fragmented Packet Dropped

SonicWall VPN says Fragmented Packet Dropped

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
SonicWall VPN says Fragmented Packet Dropped Scott Moseman 10-31-2006
Posted by Scott Moseman on October 31, 2006, 6:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
SonicWALL Firmware 5.1.7.0

When I attempt to connect to the VPN, I'm getting the error message
"Fragmented Packet Dropped" in the device logs. I tested this from my
client behind a Cisco ASA at the office, and a Linksys SOHO device from
a neighbor's house. Same error message both times.

I *do* have the "Allow Fragmented Packets" option on "Over IPSec"
checked, which I thought would have been the solution. But having that
option selected does not appear to make any difference.

Any ideas where I go from here?

Thanks,
Scott

Pure Networks
Posted by Scott Moseman on November 3, 2006, 9:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
No ideas from anyone? Should I sniff the packets? If I do, is there
even anything I'm going to find out from those packets if I do go about
collecting them? I imagine that it'll only confirm that the packets are
fragmented, and not necessarily showing me how to resolve it.

Thanks,
Scott


Scott Moseman wrote:
>
> SonicWALL Firmware 5.1.7.0
>
> When I attempt to connect to the VPN, I'm getting the error
> message "Fragmented Packet Dropped" in the device logs. I
> tested this from my client behind a Cisco ASA at the office,
> and a Linksys SOHO device from a neighbor's house. Same error
> message both times.
>
> I *do* have the "Allow Fragmented Packets" option on "Over
> IPSec" checked, which I thought would have been the solution.
> But having that option selected does not appear to make any
> difference.
>
> Any ideas where I go from here?
>
> Thanks,
> Scott
>

Posted by Simon on November 5, 2006, 5:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Scott Moseman wrote:
> No ideas from anyone? Should I sniff the packets? If I do, is there
> even anything I'm going to find out from those packets if I do go about
> collecting them? I imagine that it'll only confirm that the packets are
> fragmented, and not necessarily showing me how to resolve it.
>
> Thanks,
> Scott
>
>
> Scott Moseman wrote:
> >
> > SonicWALL Firmware 5.1.7.0
> >
> > When I attempt to connect to the VPN, I'm getting the error
> > message "Fragmented Packet Dropped" in the device logs. I
> > tested this from my client behind a Cisco ASA at the office,
> > and a Linksys SOHO device from a neighbor's house. Same error
> > message both times.
> >
> > I *do* have the "Allow Fragmented Packets" option on "Over
> > IPSec" checked, which I thought would have been the solution.
> > But having that option selected does not appear to make any
> > difference.
> >
> > Any ideas where I go from here?
> >
> > Thanks,
> > Scott
> >
Tried dropping the mtu size on the PC so that the packets don't get
fragmented ?
simon

Posted by Scott Moseman on November 6, 2006, 2:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
So the reason for the fragmented packets is, potentially, due to the MTU
size on my PC being larger than the MTU along the path somewhere? I
will play with that and see what I can break.

Thanks,
Scott


Simon wrote:
>>
>> No ideas from anyone? Should I sniff the packets? If I do, is there
>> even anything I'm going to find out from those packets if I do go
>> about collecting them? I imagine that it'll only confirm that the
>> packets are fragmented, and not necessarily showing me how to resolve it.
>>
>> Thanks,
>> Scott
>>
>>
>> Scott Moseman wrote:
>> >
>> > SonicWALL Firmware 5.1.7.0
>> >
>> > When I attempt to connect to the VPN, I'm getting the error
>> > message "Fragmented Packet Dropped" in the device logs. I
>> > tested this from my client behind a Cisco ASA at the office,
>> > and a Linksys SOHO device from a neighbor's house. Same error
>> > message both times.
>> >
>> > I *do* have the "Allow Fragmented Packets" option on "Over
>> > IPSec" checked, which I thought would have been the solution.
>> > But having that option selected does not appear to make any
>> > difference.
>> >
>> > Any ideas where I go from here?
>> >
>> > Thanks,
>> > Scott
>> >
>
> Tried dropping the mtu size on the PC so that the packets don't get
> fragmented ?
> simon
>

Posted by Simon on November 7, 2006, 11:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Scott Moseman wrote:
> So the reason for the fragmented packets is, potentially, due to the MTU
> size on my PC being larger than the MTU along the path somewhere? I
> will play with that and see what I can break.
>
> Thanks,
> Scott
>
>
> Simon wrote:
>>>
>>> No ideas from anyone? Should I sniff the packets? If I do, is there
>>> even anything I'm going to find out from those packets if I do go
>>> about collecting them? I imagine that it'll only confirm that the
>>> packets are fragmented, and not necessarily showing me how to resolve
>>> it.
>>>
>>> Thanks,
>>> Scott
>>>
>>>
>>> Scott Moseman wrote:
>>> >
>>> > SonicWALL Firmware 5.1.7.0
>>> >
>>> > When I attempt to connect to the VPN, I'm getting the error
>>> > message "Fragmented Packet Dropped" in the device logs. I
>>> > tested this from my client behind a Cisco ASA at the office,
>>> > and a Linksys SOHO device from a neighbor's house. Same error
>>> > message both times.
>>> >
>>> > I *do* have the "Allow Fragmented Packets" option on "Over
>>> > IPSec" checked, which I thought would have been the solution.
>>> > But having that option selected does not appear to make any
>>> > difference.
>>> >
>>> > Any ideas where I go from here?
>>> >
>>> > Thanks,
>>> > Scott
>>> >
>>
>> Tried dropping the mtu size on the PC so that the packets don't get
>> fragmented ?
>> simon
> >
Hi,
how did you get on ? I found in the past that some applications (Lotus
Notes was a common one) would use the largest packet they could, by the
time it's been wrapped up in the security etc it always needed
fragmentation. Might be worth checking that icmp messages are turned on
the vpn router - these should tell the client to reduce the mtu.
simon

Similar ThreadsPosted
How to make Nortel Contivity Client auto reconnect on dropped connection? March 28, 2006, 9:47 pm
Sonicwall Lan-to-Lan February 21, 2006, 11:13 am
SonicWall VPN and XP January 20, 2007, 1:22 pm
Sonicwall VPN - Windows XP August 22, 2005, 8:35 am
VPN between Astaro 6.0 and Sonicwall 4060 December 14, 2005, 10:13 pm
L2TP VPN with Sonicwall TZ170 June 17, 2006, 11:11 pm
Sonicwall to Linksys bfvp41 October 1, 2006, 7:18 pm
Safenet/Sonicwall client to Symantec 360R April 14, 2005, 12:46 am
SonicWall SOHO with Netgear Prosafe Clients? January 6, 2007, 10:41 pm
Sonicwall - The peer is not responding to phase 1 ISAKMP requests February 22, 2005, 11:09 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map