Upgrading to PAN-OS 10.1 or higher with Jumbo frames enabled might cause BGP flaps and other network issues
240
Created On 02/04/25 16:58 PM - Last Modified 06/01/26 22:29 PM
Symptom
- After perform an upgrade to PAN-OS 10.1 or higher erratic behavior in the network is reported like BGP flaps
- Both sides have Jumbo frames enabled.
- No other changes performed on the Firewall or the topology
- After downgrade to 10.0 or lower issue is solved
Environment
- PAN-OS 10.1 and above
- Jumbo Frames enabled
- PAN devices with Jumbo frames capability: PA-220, PA-400, PA-800, PA-1400, PA-3000, PA-3200, PA-3400, PA-5000, PA-5200, PA-5400, PA-7000, and PA-VM series Firewalls
Cause
-
When jumbo-frames are enabled on the firewall, the maximum MTU size (IP packet size) can be set to up to 9216 bytes. Ideally, the TCP stack should set the MSS to a high value so that the large (available) packet size can be properly utilized.
-
On PAN-OS versions 10.0 and below, the highest MSS that the MP Linux kernel can set is 4128 bytes, regardless of whether the system MTU is 4148 bytes or more.
-
On PAN-OS versions 10.1 and above, the maximum MSS that the MP Linux kernel sets depends on the actual system MTU and the full potential of 9216-byte sized packets can be utilized.
-
Upon upgrade, this change can uncover issues in customer's network that had been "masked" by the small MSS in lower PAN-OS versions
Resolution
- It is necessary to either fix the MTU settings in their network or configure the FWs to use a lower MTU value that matches their network's MTU