Juniper
JN0-332 · Question #297
You have packet loss on an IPsec VPN using the default maximum transmission unit (MTU) where the packets have the DF-bit (do not fragment) set. Which configuration solves this problem?
The correct answer is B. Set a reduced MSS value for VPN traffic under the [edit security flow tcp-mss] hierarchy. See the full explanation below for the reasoning.
Question
You have packet loss on an IPsec VPN using the default maximum transmission unit (MTU) where the packets have the DF-bit (do not fragment) set. Which configuration solves this problem?
Options
- ASet an increased MTU value on the physical interface.
- BSet a reduced MSS value for VPN traffic under the [edit security flow tcp-mss] hierarchy.
- CSet a reduced MTU value for VPN traffic under the [edit security flow] hierarchy.
- DSet an increased MSS value on the st0 interface.
How the community answered
(37 responses)- A8% (3)
- B84% (31)
- C5% (2)
- D3% (1)
Community Discussion
No community discussion yet for this question.