Problem description
I am seeking assistance regarding enabling out-of-order IP fragment reassembly for my FortiGate NVA's public IP in Azure. My resource is experiencing issues with fragmented UDP packets over IPsec tunnels, where fragments are arriving out of order or missing, impacting tunnel connectivity.
Environment
Azure Virtual Network in Canada Central with a FortiGate NVA VM running FortiOS 7.4.12 on a Standard_DS2_v2 instance, external NIC with accelerated networking, and a Standard SKU public IP.
What I've already tried
I reviewed the support case details and available Microsoft guidance on NVA scenarios. I examined the case history and diagnostic outputs, noting that no specific Azure setting was documented to enable out-of-order IP fragment reassembly. I also checked for network security groups, user-defined routes, and routing behavior, but found no configuration changes or diagnostic insights that address the fragment loss issue.
Current status
The issue persists: the first IP fragment often arrives, but subsequent fragments are frequently missing or arriving out of order. I am seeking clarification on whether Azure can support enabling out-of-order IP fragment reassembly for this scenario, and if not, what mitigation strategies are recommended to improve UDP traffic delivery over IPsec tunnels.