TCP MSS Adjustment Limitations
- When TCP MSS adjustment is enabled on an interface, some delay in the TCP connection is established. Since we support MSS adjustment on ingress and egress traffic of an interface as well as for both SYN and SYN-ACK packets, 2 packets are trapped to CPU (Ingress SYN and egress SYN-ACK) for one TCP connection
- TCP MSS adjustment is not supported for OpenFlow packets.
- When TCP SYN attack and TCP MSS adjustment are configured on an interface, TCP MSS adjustment takes the higher priority.
- When PBR and TCP MSS adjustment both are applied, the TCP connections that go through PBR may be delayed, even if the outgoing interface of the PBR route does not have the TCP MSS adjustment configuration.
- When MSS is configured on the outgoing interface that PBR points to, but not on the outgoing interface that Layer 3 lookup points to, then the packet is not be trapped to the CPU. The MSS is not modified for the packet. For example, assume the normal route lookup for incoming packet with destination address 10.10.10.10 goes through 1/1/10. But PBR is configured for redirecting the packet with destination address 10.10.10.10 to 1/1/1. TCP MSS is configured on interface 1/1/1. Now MSS is not modified for the TCP SYN packet coming with destination address 10.10.10.10 even though it goes via MSS configured interface 1/1/1.
- TCP MSS adjustment ACL rules are given higher priority than the user-defined ACL rules. Therefore even if the user-defined rule is applied to drop the TCP packets, it comes to the CPU because of the TCP MSS adjustment rule and it is dropped in software.
- In case of ECMP routes for a destination, there is no guarantee that the packet will go through the path chosen in hardware. The outgoing TCP SYN/SYN-ACK packet will be trapped to the CPU and the MSS is modified according to the software route lookup.
- When TCP MSS adjustment is applied on a physical, VE, or LAG interface, it will modify the MSS only for the plain IP of IPv6 traffic.. It will not modify the MSS for tunneled or encrypted packets. The MSS value cannot be modified for an AH-only IPsec packet (unencrypted). The MD5/SHA-1 hash cannot be recomputed because the security keys to compute the hash value are unknown.
- TCP MSS adjustment configuration is not supported on loopback and management interfaces.
- TCP MSS adjustment is supported only on the Layer 3 interface.
- When TCP MSS is applied on physical, VE, or LAG interfaces, the MSS will be modified for plain IP and IPv6 traffic only. The MSS will not be modified for tunneled or encrypted packets.