TCP MSS Adjustment Limitations
- When TCP MSS adjustment is enabled on an interface, some delay occurs in the TCP connection. Because the ICX device supports MSS adjustment on ingress and egress traffic of an interface as well as for both SYN and SYN-ACK packets, two packets are trapped to the CPU (Ingress SYN and egress SYN-ACK) for one TCP connection.
- TCP MSS adjustment is not supported for OpenFlow packets.
- When TCP SYN attack and TCP MSS adjustment are configured on an interface, TCP MSS adjustment takes the higher priority.
- When policy-based routing (PBR) and TCP MSS adjustment are both applied, the TCP connections that go through PBR may be delayed, even if the outgoing interface of the PBR route does not have the TCP MSS adjustment configuration.
- When MSS is configured on the outgoing interface that PBR points to, but not on the outgoing interface that Layer 3 lookup points to, the packet is not trapped to the CPU. The MSS is not modified for the packet. For example, suppose the normal route lookup for an incoming packet with the destination address 10.10.10.10 goes through interface 1/1/10, but PBR is configured for redirecting a packet with destination address 10.10.10.10 to interface 1/1/1. If TCP MSS is configured on interface 1/1/1, MSS is not modified for the TCP SYN packet arriving with destination address 10.10.10.10 even though it traverses MSS-configured interface 1/1/1.
- TCP MSS adjustment ACL rules are given higher priority than the user-defined ACL rules. Therefore, even if the user-defined rule is applied to drop TCP packets, a TCP packet comes to the CPU because of the TCP MSS adjustment rule and is dropped in software.
- For ECMP destination routes, there is no guarantee that the packet will go through the path chosen in hardware. The outgoing TCP SYN/SYN-ACK packet will be trapped to the CPU, and the MSS is modified according to the software route lookup.
- When TCP MSS adjustment is applied on a physical, VE, or LAG interface, the MSS is modified only for plain IP or IPv6 traffic. The MSS for tunneled or encrypted packets is not modified.
- The MSS value cannot be modified for an AH-only IPsec packet (unencrypted). The MD5/SHA-1 hash cannot be recomputed because the security keys to compute the hash value are unknown.
- TCP MSS adjustment configuration is not supported on loopback or management interfaces.
- TCP MSS adjustment is supported only on the Layer 3 interface.