Virtual Network: Out-of-order IP fragment reassembly for FortiGate NVA — Support inquiry

David Grenon Cloud ADM 0 Reputation points
2026-09-29T21:08:36.4333333+00:00

Problem description

I am seeking assistance regarding enabling out-of-order IP fragment reassembly for my FortiGate NVA's public IP in Azure. My resource is experiencing issues with fragmented UDP packets over IPsec tunnels, where fragments are arriving out of order or missing, impacting tunnel connectivity.

Environment

Azure Virtual Network in Canada Central with a FortiGate NVA VM running FortiOS 7.4.12 on a Standard_DS2_v2 instance, external NIC with accelerated networking, and a Standard SKU public IP.

What I've already tried

I reviewed the support case details and available Microsoft guidance on NVA scenarios. I examined the case history and diagnostic outputs, noting that no specific Azure setting was documented to enable out-of-order IP fragment reassembly. I also checked for network security groups, user-defined routes, and routing behavior, but found no configuration changes or diagnostic insights that address the fragment loss issue.

Current status

The issue persists: the first IP fragment often arrives, but subsequent fragments are frequently missing or arriving out of order. I am seeking clarification on whether Azure can support enabling out-of-order IP fragment reassembly for this scenario, and if not, what mitigation strategies are recommended to improve UDP traffic delivery over IPsec tunnels.

Azure Virtual Network
Azure Virtual Network

An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.


2 answers

Sort by: Most helpful
  1. kagiyama yutaka 5,575 Reputation points
    2026-09-30T04:04:05.4166667+00:00

    I think Azure drops out-of-order fragments arriving at the VM, and fragmented packets take the nonaccelerated path. TCP MSS clamping does not address UDP, so avoid IP fragmentation. Check the path MTU first, then adjust the FortiGate tunnel MTU.

    Was this answer helpful?

    0 comments No comments

  2. JonathanPe 17,675 Reputation points Moderator
    2026-09-30T00:48:33.27+00:00

    Hi @David Grenon Cloud ADM

    As far as I'm aware, there is no Azure Virtual Network or Public IP setting that allows customers to enable out-of-order IP fragment reassembly for traffic destined to an NVA. The reassembly of fragmented packets is typically handled by the destination host or appliance, not by an Azure Public IP resource. Given your symptoms (fragmented UDP traffic over IPsec, missing later fragments, and packet ordering concerns), the usual mitigations are:

    • Reduce packet size and adjust MTU/MSS values to avoid fragmentation where possible.
    • Enable IPsec fragmentation handling features supported by the FortiGate platform.
    • Validate whether UDP encapsulated traffic can be tuned to remain below the path MTU.
    • Capture traffic on both sides of the tunnel to determine whether fragments are being dropped before reaching the NVA. (General troubleshooting suggestion.)

    Based on the information provided, I am not aware of an Azure feature that can be enabled on a Standard SKU Public IP or NIC specifically to force fragment reordering or reassembly before delivery to the FortiGate NVA.

    If Microsoft Support has already reviewed the case and no Azure configuration option was identified, the next step would likely be to investigate MTU/fragmentation behavior and FortiGate-specific handling of fragmented IPsec traffic rather than an Azure networking setting.

    If this helps clarify the Azure side of the issue, please mark the answer as helpful or accepted so others troubleshooting fragmented IPsec traffic with NVAs can find it more easily.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.