Upgrading to PAN-OS 10.1 or higher with Jumbo frames enabled might cause BGP flaps and other network issues

Upgrading to PAN-OS 10.1 or higher with Jumbo frames enabled might cause BGP flaps and other network issues

240
Created On 02/04/25 16:58 PM - Last Modified 06/01/26 22:29 PM


Symptom


  • After perform an upgrade to PAN-OS 10.1 or higher erratic behavior in the network is reported like BGP flaps
  • Both sides have Jumbo frames enabled.
  • No other changes performed on the Firewall or the topology
  • After downgrade to 10.0 or lower issue is solved


Environment


  • PAN-OS 10.1 and above
  • Jumbo Frames enabled
  • PAN devices with Jumbo frames capability: PA-220, PA-400, PA-800, PA-1400, PA-3000, PA-3200, PA-3400, PA-5000, PA-5200, PA-5400, PA-7000, and PA-VM series Firewalls


Cause


  • When jumbo-frames are enabled on the firewall, the maximum MTU size (IP packet size) can be set to up to 9216 bytes. Ideally, the TCP stack should set the MSS to a high value so that the large (available) packet size can be properly utilized.

  • On PAN-OS versions 10.0 and below, the highest MSS that the MP Linux kernel can set is 4128 bytes, regardless of whether the system MTU is 4148 bytes or more.

  • On PAN-OS versions 10.1 and above, the maximum MSS that the MP Linux kernel sets depends on the actual system MTU and the full potential of 9216-byte sized packets can be utilized.

  • Upon upgrade, this change can uncover issues in customer's network that had been "masked" by the small MSS in lower PAN-OS versions



Resolution


  1. It is necessary to either fix the MTU settings in their network or configure the FWs to use a lower MTU value that matches their network's MTU 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpcHCAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail