Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Modification of the interface MTU

Hi all!

Quick question regarding XGS 126: MTU is a property of the physical interface. If I want to reduce the MTU for a VLAN I have to do it on the physical interface.

By adjusting MTU value I seem to lose the VLAN interface and the associated dependencies e.g. firewall rules.

Is there a way to prevent this?

Thank you for your input! nk



This thread was automatically locked due to age.
Parents Reply
  • Just tried this out, the VLAN ist still there even if I change both MTU and MSS.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Hallo Philipp!

    thanks for trying. Did you make the change via WBM or CLI?

    When I use WBM I get this message: SFOS 19.0.0 GA-Build317, 23.01.2023

  • try with the CLI command I mentioned above in the e.g, and leave the mtu default just change the required mss value !

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi Vivek!

    The MSS adjustment solves the problem only for TCP connections. I will propose this to the customer but I don't expect him to agree to the solution.

    Background: It is a network in an industrial facility where the PRP protocol is used. There is a valid network layout in which connections to "single attached nodes" are established. When using PRP the packet is lengthened by a 6Byte trailer by a PRP switch. Neither the endpoints nor the firewall are involved. Packets with max payload can therefore exceed the MTU of the recipient. The requirement is that at least routed connections can be established without interface configuration at the endpoints. This should be transport layer independent.

  • As of now this can be consider a workaround or a probable solution. What are your customer's expectation as a solution then ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi!

    This is a short-term workaround (MSS config). Previously we used UTM instead of XG with reduced MTU but we missed that detail when switching to XGS. The goal is therefore a reduced MTU again.

    I had hoped that there is a way to correct the MTU without serious effects.. I will reduce the MTU in any case and restore the lost configuration.

    Thanks for your support!

  • I used the CLI, as Vivek suggested.

    To my surprise, changing BOTH values and changig EITHER value did not "destroy" my defined VLAN-Port.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Thank you  , I am glad my suggestion works !

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Philipp vielen Dank!

    I will try CLI instead of WBM as soon as possible. Would also be very interesting if these settings are persistent and why it behaves differently in CLI than via WBM config.

  • Yes they are persistent  , sure you can let me know your feedback on this !

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Today I had contact with another SFOS specialist and we were able to discuss the issue. The change is to be made on an active-passive HA cluster(new information in this post... I know). He said I should break up the cluster, make the change via CLI and set up the cluster again. Problem: I lose Node2 because I don't have remote access to the OOB interface.

    At that point, unfortunately, I can no longer use the CLI and have to work using the WBM. Perhaps someone would like to comment on the problem with cluster because the information may still be useful for other users.

    Thanks for all Comments I appreciate the help very much!