Description

SRX dropped the received ISAKMP packet that had been fragmented. This packet reached a length of 1902 bytes due to its X-509 certificate payload and was consequently fragmented by the upstream network device.





Solution

Remove or deactivate below screen options:


set security screen ids-option anti-attack ip block-frag


  • block-frag—Enable IP packet fragmentation blocking

https://www.juniper.net/documentation/us/en/software/junos/denial-of-service/topics/topic-map/security-ip-attack.html#id-example-dropping-fragmented-ip-packets


https://www.juniper.net/documentation//us/en/software/junos/cli-reference/topics/ref/statement/security-edit-ip-screen.html





Modification History

New article created