Fragmented UDP packets blocked

DOWNLOAD THE LATEST FIRMWARE HERE
FuzzyDice
Member
 
Posts: 7
Joined: Thu Jan 05, 2017 4:47 am
Has thanked: 0 time
Been thanked: 0 time

Fragmented UDP packets blocked

Thu Jan 05, 2017 5:22 am

Hello everyone.

I am seeing fragmented UDP packets being blocked at my WS-10-250-AC, firmware 1.4.5. Here is a permalink to one of the tests I did using the ICSI Netalyzr tool:

http://n2.netalyzr.icsi.berkeley.edu/re ... ca-af7a/rd

When I bypass the Netonix switch the tool reports no blockage of UDP fragments.

I can go into more detail about my network setup and configuration if needed, but before doing that I wanted to see if there was a setting or something in the switch that affects this? I poked around and couldn't find anything that seemed related to this issue, but my wife will tell you I couldn't find the water from a boat. :roll:

Thanks!

User avatar
Eric Stern
Employee
Employee
 
Posts: 532
Joined: Wed Apr 09, 2014 9:41 pm
Location: Toronto, Ontario
Has thanked: 0 time
Been thanked: 130 times

Re: Fragmented UDP packets blocked

Thu Jan 05, 2017 12:28 pm

You can try increasing the MTU on the Ports tab.

FuzzyDice
Member
 
Posts: 7
Joined: Thu Jan 05, 2017 4:47 am
Has thanked: 0 time
Been thanked: 0 time

Re: Fragmented UDP packets blocked

Thu Jan 05, 2017 1:31 pm

Currently set to 1528, with the rest of the network set to 1500. The WAN link is 1500, so that's going to be the maximum path MTU regardless.

The problem isn't that the packets are being fragmented - that's going to happen regardless since the path MTU will always be max 1500. The problem is that fragmented UDP packets aren't making it past the Netonix for some reason. If I run this test with the Netonix bypassed the fragmented UDP packets are passed across the entire path, including the WAN link.

I have customers using a variety of VOIP, VPN, and IPSec connections which all pass the occasional jumbo UDP frame and it's causing disruption to their services when the fragments are being blocked. With the popularity of Netonix among WISPs I would have expected this issue to have surfaced, so I'm not sure if this is expected behavior from the Netonix or if I have a special problem.

User avatar
Eric Stern
Employee
Employee
 
Posts: 532
Joined: Wed Apr 09, 2014 9:41 pm
Location: Toronto, Ontario
Has thanked: 0 time
Been thanked: 130 times

Re: Fragmented UDP packets blocked

Thu Jan 05, 2017 4:57 pm

I tested this with the switches in my lab and it passes every time. I tried a number of configuration changes to try and cause it to happen.

If you'd like to send me backup of the configuration of your switch I can look at it. You can email it to eric@netonix.com.

But I can't think of any configuration issue that could be causing this, as the switch operates at layer 2 and thus it doesn't know or care what is going on at layer 4 (UDP).

User avatar
Eric Stern
Employee
Employee
 
Posts: 532
Joined: Wed Apr 09, 2014 9:41 pm
Location: Toronto, Ontario
Has thanked: 0 time
Been thanked: 130 times

Re: Fragmented UDP packets blocked

Tue Jan 10, 2017 6:53 pm

I was able to duplicate this problem using your configuration.

On the Ports tab disable DHCP Snooping (DS) on all your ports.

FuzzyDice
Member
 
Posts: 7
Joined: Thu Jan 05, 2017 4:47 am
Has thanked: 0 time
Been thanked: 0 time

Re: Fragmented UDP packets blocked

Tue Jan 10, 2017 7:27 pm

That was it - thank you!

User avatar
michwave
Member
 
Posts: 13
Joined: Tue Jul 28, 2015 9:04 am
Location: WEST MICHIGAN
Has thanked: 4 times
Been thanked: 0 time

Re: Fragmented UDP packets blocked

Sun Jul 23, 2017 9:24 am

Is this going to get resolved? Will we be able to use DHCP snooping again?

User avatar
Eric Stern
Employee
Employee
 
Posts: 532
Joined: Wed Apr 09, 2014 9:41 pm
Location: Toronto, Ontario
Has thanked: 0 time
Been thanked: 130 times

Re: Fragmented UDP packets blocked

Sun Jul 23, 2017 10:35 am

I'll look into it.

User avatar
michwave
Member
 
Posts: 13
Joined: Tue Jul 28, 2015 9:04 am
Location: WEST MICHIGAN
Has thanked: 4 times
Been thanked: 0 time

Re: Fragmented UDP packets blocked

Wed Aug 30, 2017 7:03 pm

I'm surprised many others haven't run into this with VPNs being blocked. Any update on this?

Thanks
Jon

Return to Hardware and software issues

Who is online

Users browsing this forum: No registered users and 39 guests