The other day, I was troubleshooting an issue where users reported that “some websites are working while some are not“. Uh. This is almost the worst scenario to face from a networker’s perspective. It’s way easier if things do or don’t work at all, but not this “some don’t” situation.
The scenario: Using Zscaler for outbound Internet connections, connected via a GRE tunnel from a Palo Alto Networks firewall. TL;DR: If it’s not DNS, it’s MTU. đ The “Suppress ICMP Frag Needed” option within the ICMP Drop section of the Zone Protection Profile did what it is meant to do: block “ICMP fragmentation needed” messages. Unfortunately, this killed *some* sessions which had the “Don’t fragment” bit set but exceeded the (lower) MTU of the GRE tunnel.
Continue reading It was MTU! Zscaler over GRE behind Palo, blocking ICMP Frag Needed
Begriffe wie SASE, ZTA oder OT begegnen uns im Alltag stĂ€ndig â in Projekten, in Meetings, auf Konferenzen. Doch wie oft bleibt davon wirklich was hĂ€ngen? Und was davon ist mehr Marketing als Substanz?