SRX Services Gateway
Highlighted
SRX Services Gateway

SRX and tcp-mss all-tcp

‎02-03-2020 08:28 PM

Hello Community,

 

Question for folks who know SRX in depth. if one does tcp-mss all-tcp, will SRX adjust mss for tunneled traffic like VxLAN thats passing through it. The 'through' traffic in this case will be the UDP tunnel/VxLAN encaped traffic.

 

I am interested in this as i am looking to do VxLAN over internet and SRX with IPSec to encrypt the traffic. Has anyone tried this before?

 

Thanks

3 REPLIES 3
Highlighted
SRX Services Gateway

Re: SRX and tcp-mss all-tcp

‎02-03-2020 09:00 PM

Hi, unfortunately SRX can not adjust mss for tunneled traffic. 

Highlighted
SRX Services Gateway

Re: SRX and tcp-mss all-tcp

‎02-03-2020 09:07 PM

Hi,

 

As VXLAN traffic is UDP encapsulated, the TCP MSS settings simply do not apply to the VXLAN traffic.

 

Hope this helps.

 

Thanks and Regards,

Pradeep Kumar M

Highlighted
SRX Services Gateway

Re: SRX and tcp-mss all-tcp

‎02-04-2020 07:00 AM

Thank you for the response.