Troubleshooting failed calls caused by large SIP messages over UDP
Verified 2026-10-02 · 55 sources · tier 1–5
Also known as large-sip-invite-fragmentation, sip-udp-fragmentation.
Cisco's BroadWorks tech note says routers commonly block fragmented UDP, and RFC 8085 notes that losing a single IP fragment loses the whole reassembled datagram and that NATs and firewalls may discard fragments 5 42. SonicWall and Fortinet each document fragmented UDP being dropped by their devices, and Cisco IOS voice gateways, PJSIP and Kamailio can send oversized SIP messages over TCP instead 51 23 16 32 28.
How large SIP messages break over UDP
RFC 8085 says applications SHOULD NOT send UDP datagrams that result in IP packets exceeding the MTU along the path 43. For UDP applications that cannot discover path MTU, RFC 8085 gives the effective send MTU as the smaller of 576 bytes and the first-hop MTU for IPv4, and as 1280 bytes for IPv6 41. RFC 8900 says developers SHOULD NOT develop new protocols or applications that rely on IP fragmentation 48.
- Non-initial IP fragments carry no transport-layer port information, so a stateless firewall must either accept all subsequent fragments or block them, possibly blocking legitimate traffic 50.
- RFC 8900 states that NAT devices must virtually reassemble fragmented packets in order to translate and forward each fragment 46.
- RFC 8900 cites a measurement in which at least 28% of sampled paths did not convey packets containing the IPv6 Fragment extension header 45.
- Cisco's BroadWorks tech note says routers commonly block fragmented UDP because they must buffer fragments until the whole message arrives, and attackers can exploit that buffering to exhaust memory 5.
Field reports suggest that IMS headers added by CSCF elements, together with SDP offering AMR and EVS codecs, push INVITEs past 1300 bytes 20.
We infer that when one fragment of a SIP-over-UDP INVITE is dropped, the receiver never gets the INVITE, so the caller sees only its own retransmissions followed by a timeout rather than an error response from the far end 26.
Tunnels and path MTU discovery
RFC 4459 describes how tunnelling (IP-in-IP, GRE, L2TP, IPsec) adds encapsulation headers, so a source must size packets to fit the smallest MTU on the path after encapsulation 40. Cisco states that GRE encapsulation adds 24 bytes to a packet 9. Cisco also states that IPsec adds at least 1 IPv4 header, and that ESP with ESP authentication overhead does not exceed roughly 58 bytes 12. When GRE is combined with IPsec, Cisco recommends setting the GRE tunnel IP MTU to 1400 bytes to absorb both overheads 10.
- Cisco notes that PMTUD depends on ICMP Destination Unreachable type 3 code 4 messages, and that filters which block all ICMP types break it 11.
- RFC 4459 says PMTUD signalling for tunnels is unreliable in IPv4 because firewalls and other boxes are often configured to drop all ICMP 39.
- RFC 8900 explains that persistent loss of ICMP Packet Too Big messages causes persistent path MTU black holes 49.
- RFC 8900 says network operators MUST NOT filter ICMPv6 Packet Too Big messages unless they are known to be forged 47.
RFC 8085 recommends PMTUD or Packetization Layer PMTUD for UDP applications, and notes that PLPMTUD avoids depending on ICMP messages that middleboxes often filter 44.
Cisco documents that ip tcp adjust-mss works by reducing the MSS value carried in TCP SYN packets 8. WarmTransfer's reading of the sources is that MSS clamping therefore cannot stop a SIP-over-UDP INVITE larger than the tunnel MTU from being fragmented, and that it helps SIP only after signalling moves to TCP or TLS 1.
Diagnosing it
In SonicWall's documented case, calls from external sources worked while some internal calls failed, because only the larger internal INVITEs were fragmented 53. SonicWall documents that SonicOS 5.8 and later drops fragmented SIP over UDP and logs "242 Packet dropped - failed processing" 51.
Fortinet documents that NP7-based FortiGates with an IPS profile may drop fragmented UDP packets with payloads of 1636 to 1722 bytes on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0 23. On NP7 FortiGates, NTurbo fragmentation drops are identified by running diagnose test app ipsmonitor 14 and watching the drop(decode) counter increase 22.
Palo Alto Networks firewalls reassemble fragmented traffic for content inspection only, then forward it fragmented according to the egress interface MTU 30. PAN-OS global counters for fragments include flow_ipfrag_recv, flow_ipfrag_merge and flow_ipfrag_frag, plus flow_fwd_ip_df for packets dropped because DF was set and the MTU was exceeded 29.
Moving signalling to TCP or TLS
WarmTransfer's reading of the sources is that moving SIP signalling from UDP to TCP or TLS removes dependence on IP fragmentation for large messages because TCP segments data to the negotiated MSS, which is why vendors give it as the primary fix 54. In the field, practitioners report that switching SIP to TCP is often impractical, because many peers do not have TCP enabled or reachable, especially behind NAT 21.
Cisco IOS voice gateways and CUBE
- Dial-peer command: On Cisco IOS voice gateways and CUBE,
voice-class sip transport switch udp tcpswitches a SIP request from UDP to TCP when the request size exceeds the MTU size 16. - Default and release: The command is disabled by default 15. It was introduced in Cisco IOS Release 12.3(8)T 14.
- Global command: Cisco's command reference also describes a global transport switch command that switches transport for SIP messages larger than 1300 bytes. It states that the dial-peer command takes precedence over the global command 13.
Cisco Unified CM
In a Cisco Unified CM 12.5(1) SIP trunk security profile with Device Security Mode set to Non Secure, the incoming transport type is TCP+UDP, while with Authenticated or Encrypted it is TLS 17. The same 12.5(1) security guide says to use UDP as the SIP trunk outgoing transport only when the far end does not support TCP, and otherwise to use TCP as the default 18.
Cisco BroadWorks and Polycom phones
- Transport switching: Cisco BroadWorks handles large SIP messages by switching them to TCP rather than relying on UDP fragmentation. Transport can be set to UDP, TCP or unspecified per interface, network server, media server and routing NE 7.
- Enabling TCP: The Application Server parameter
supportTcpunder AS_CLI/Interface/SIP enables TCP for SIP 6. - Polycom phones: Cisco's BroadWorks note states that Polycom phones can be set to TCPOnly, TCPpreferred or DNSnaptr transport so that large SIP messages avoid UDP 33.
PJSIP and Asterisk
- PJSIP threshold: In PJSIP 2.12.1,
PJSIP_UDP_SIZE_THRESHOLDdefaults to 1300 bytes. Requests larger than this are sent over TCP when TCP switching is enabled 32. - PJSIP switching default: In PJSIP 2.12.1,
PJSIP_DONT_SWITCH_TO_TCPdefaults to 0, so automatic UDP-to-TCP switching is on. It can be changed at runtime throughdisable_tcp_switchinpjsip_cfg_t31. - Asterisk default: In Asterisk res_pjsip, the [system] option
disable_tcp_switchdefaults to yes. Asterisk therefore does not automatically switch large outgoing requests from UDP to TCP unless configured to 2. - Asterisk TCP requirement: Asterisk documentation warns that when the TCP switch is enabled, a large message switched to TCP fails if no TCP transport is configured or the remote side is not listening on TCP 4.
- Asterisk interoperability: The Asterisk sample pjsip.conf warns that turning off
disable_tcp_switchhas been known to cause interoperability issues 3.
Kamailio
The Kamailio core parameters udp_mtu and udp_mtu_try_proto let the proxy send a message over another protocol, such as TCP, when it would exceed the configured UDP MTU 28. Setting Kamailio's pmtu_discovery core parameter to 1 sets the don't-fragment bit on outbound IP packets; the parameter defaults to 0 27.
Microsoft Teams Direct Routing
Microsoft Teams Direct Routing signalling is SIP over TLS, with the SBC connecting to the Microsoft SIP proxy on port 5061, and no UDP signalling option is listed 55.
Shrinking messages
SonicWall's fix for dropped fragmented INVITEs is to shrink SIP messages below the MTU by removing unnecessary headers, or to move signalling to SIP over TCP 52.
Field reports suggest that practitioners trimming SIP to avoid UDP fragmentation commonly remove User-Agent or Server, Allow, Date and Timestamp headers and prune unused codecs from the SDP, treating them as low-risk removals 19.
Firewall-side workarounds
Fortinet's workarounds for NP7 fragmented-UDP drops include enabling NPU IP reassembly (config system npu, config ip-reassembly, set status enable), disabling auto-asic-offload on the policy, or removing the IPS sensor 24.
Fortinet states that NP7 IP reassembly handles packets fragmented into at most 2 pieces, and that for 3 or more fragments NTurbo must be disabled 25.
See also
- Troubleshooting SIP 408 Request Timeout and calls that get no response
- SIP retransmission timers and transaction state
- SIP capture and analysis with Wireshark and sngrep and HOMER
- SIP ALG problems on firewalls and routers
- SD-WAN considerations for voice
- SIP TLS handshake failures on trunks
- SDP offer answer and codec negotiation
- NAT traversal ICE STUN and TURN
Applicability
Applies to: Cisco BroadWorks, SonicWall SonicOS, Fortinet FortiGate, Cisco Unified Border Element, Teluu PJSIP, Kamailio project, Cisco IOS XE, Palo Alto Networks PAN-OS, Cisco Unified Communications Manager, Poly UC Software, Sangoma Asterisk, and Microsoft Teams Direct Routing. Deployments: on-premises and multi-tenant. Sources checked 2026-10-02. The Cisco IOS voice-class sip transport switch command applies to Cisco IOS Release 12.3(8)T and later, where it was introduced 14. The Cisco Unified CM transport settings described here come from the Release 12.5(1) security guide 18. The PJSIP defaults described here are those of PJSIP 2.12.1 32. The Fortinet fragmented-UDP drop applies to NP7-based FortiGates on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0 23. The SonicWall behaviour is documented for SonicOS 5.8 and later 51.
What remains uncertain
- SD-WAN: SD-WAN tunnel MTU defaults and their effect on voice fragmentation are not covered by the sources below.
- SIP specification: The SIP specification's own wording on transport selection and message size is not covered by the sources below.
- Cisco Unified CM auto-switching: Whether Cisco Unified CM automatically switches oversized SIP messages from UDP to TCP on SIP trunks is not covered by the sources below.
- CUBE message trimming: CUBE configuration for removing headers and SDP lines to shrink SIP messages is not covered by the sources below.
- Phone vendor guides: Phone transport settings as documented in phone vendors' own admin guides are not covered by the sources below.
- Packet capture: A packet-capture method for showing fragments leaving one point on a SIP path and not arriving at another is not covered by the sources below.
- SIP ALG and reassembly: The interaction between SIP ALG inspection and fragment reassembly on firewalls is not covered by the sources below.
- Current SonicOS releases: Whether current SonicOS releases still drop fragmented SIP over UDP is not covered by the sources below.
See also
Related to
- SD-WAN considerations for voice — Tunnel and VPN overhead lowers the effective path MTU and makes previously safe SIP message sizes fragment.
- SIP ALG problems on firewalls and routers — Firewall SIP ALGs and inspection engines are a common place where fragmented SIP over UDP is dropped or mishandled.
- SIP TLS handshake failures on trunks — Moving SIP from UDP to TLS is a standard remedy; it then exposes TLS handshake failure modes.
- SIP capture and analysis with Wireshark and sngrep and HOMER — Diagnosis depends on captures on both sides of the suspect hop to see IP fragments leave and fail to arrive.
- Troubleshooting SIP 408 Request Timeout and calls that get no response — A large INVITE whose fragments are dropped is never delivered; the UAC retransmits and eventually times out; so the visible symptom is often a 408 or a silent timeout.
Referenced by
- Troubleshooting SIP 408 Request Timeout and calls that get no response — large UDP INVITEs lost to fragmentation present as no-response timeouts
Sources
- 1Because MSS clamping rewrites only TCP SYN options, it cannot stop a SIP-over-UDP INVITE larger than the tunnel MTU from being fragmented; it helps SIP only after signalling moves to TCP or TLS.inferredResolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · ip tcp adjust-mss section · Checked 2026-10-02
- 2In Asterisk res_pjsip the [system] option disable_tcp_switch defaults to yes, so Asterisk does not automatically switch large outgoing requests from UDP to TCP unless configured to.configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch) · [system] section, disable_tcp_switch comment block · Checked 2026-10-02
- 3The Asterisk sample pjsip.conf warns that turning off disable_tcp_switch has been known to cause interoperability issues.configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch) · [system] section, disable_tcp_switch comment block · Checked 2026-10-02
- 4Asterisk documentation warns that if the TCP switch is enabled, a large message switched to TCP fails when no TCP transport is configured or the remote side is not listening on TCP.PJSIP Transport Selection - Asterisk Documentation · Changeover to TCP when sending via UDP · Checked 2026-10-02
- 5Cisco's BroadWorks tech note says routers commonly block fragmented UDP because they must buffer fragments until the whole message arrives, which attackers can exploit to exhaust memory.Working with large SIP packets · Problem section · Checked 2026-10-02
- 6In Cisco BroadWorks, the Application Server parameter supportTcp under AS_CLI/Interface/SIP enables TCP for SIP.Working with large SIP packets · Solution section, AS_CLI/Interface/SIP · Checked 2026-10-02
- 7Cisco BroadWorks handles large SIP messages by switching them to TCP rather than relying on UDP fragmentation, with transport settable per interface, network server, media server and routing NE as UDP, TCP or unspecified.Working with large SIP packets · Solution section · Checked 2026-10-02
- 8Cisco documents that ip tcp adjust-mss works by reducing the MSS value carried in TCP SYN packets.Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · ip tcp adjust-mss section · Checked 2026-10-02
- 9Cisco states that GRE encapsulation adds 24 bytes to a packet.Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE and IPsec overhead discussion · Checked 2026-10-02
- 10Cisco recommends setting the GRE tunnel IP MTU to 1400 bytes when GRE is combined with IPsec, to absorb both overheads.Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE over IPsec recommendations · Checked 2026-10-02
- 11Cisco notes that PMTUD depends on ICMP Destination Unreachable type 3 code 4 messages and that filters which block all ICMP types break it.Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · PMTUD and ICMP filtering section · Checked 2026-10-02
- 12Cisco states that IPsec adds at least one IPv4 header and that ESP with ESP authentication overhead does not exceed roughly 58 bytes.Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE and IPsec overhead discussion · Checked 2026-10-02
- 13Cisco's command reference describes a global transport switch command that switches transport for SIP messages larger than 1300 bytes, and states the dial-peer voice-class sip transport switch command takes precedence over it.Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Usage Guidelines and Related Commands table · Checked 2026-10-02
- 14The voice-class sip transport switch command was introduced in Cisco IOS Release 12.3(8)T.Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Command History · Checked 2026-10-02
- 15The voice-class sip transport switch dial-peer command is disabled by default.Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Command Default · Checked 2026-10-02
- 16On Cisco IOS voice gateways and CUBE, the dial-peer command voice-class sip transport switch udp tcp switches a SIP request from UDP to TCP when the request size exceeds the MTU size.Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Syntax Description · Checked 2026-10-02
- 17In a Cisco Unified CM 12.5(1) SIP trunk security profile with Device Security Mode Non Secure, the incoming transport type is TCP+UDP; with Authenticated or Encrypted it is TLS.Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup · Table 1 SIP Trunk Security Profile Configuration Settings, Incoming Transport Type · Checked 2026-10-02
- 18Cisco's Unified CM 12.5(1) security guide says to use UDP as the SIP trunk outgoing transport only when the far end does not support TCP, and otherwise to use TCP as the default.Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup · Table 1 SIP Trunk Security Profile Configuration Settings, Outgoing Transport Type note · Checked 2026-10-02
- 19Practitioners trimming SIP to avoid UDP fragmentation commonly remove User-Agent or Server, Allow, Date and Timestamp headers and prune unused codecs from SDP, treating them as low-risk removals.field reportSIP UDP fragmentation and Kamailio: the SIP header diet · Section listing safe header removals · Checked 2026-10-02
- 20Practitioners report that IMS headers added by CSCF elements and SDP offering AMR and EVS codecs push INVITEs past 1300 bytes.field reportSIP and UDP Fragmentation · Root causes discussion · Checked 2026-10-02
- 21Practitioners report that switching SIP to TCP is often impractical in the field because many peers do not have TCP enabled or reachable, especially behind NAT.field reportSIP UDP fragmentation and Kamailio: the SIP header diet · Discussion of TCP as alternative · Checked 2026-10-02
- 22On NP7 FortiGates, NTurbo fragmentation drops are identified with diagnose test app ipsmonitor 14 by watching the drop(decode) counter increase.Technical Tip: How to Identify UDP NTurbo fragmentation drops and how to resolve them on NP7 FortiGates · Identification section · Checked 2026-10-02
- 23Fortinet documents that NP7-based FortiGates with an IPS profile may drop fragmented UDP packets with payloads of 1636 to 1722 bytes on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0.Technical Tip: Fragmented UDP packets with payload sizes in 1636-1722 byte range may be dropped · Description and Scope sections · Checked 2026-10-02
- 24Fortinet's workarounds for NP7 fragmented-UDP drops include enabling NPU IP reassembly (config system npu, config ip-reassembly, set status enable), disabling auto-asic-offload on the policy, or removing the IPS sensor.Technical Tip: Fragmented UDP packets with payload sizes in 1636-1722 byte range may be dropped · Workaround section · Checked 2026-10-02
- 25Fortinet states NP7 IP reassembly handles packets fragmented into at most two pieces; for three or more fragments NTurbo must be disabled.Technical Tip: How to Identify UDP NTurbo fragmentation drops and how to resolve them on NP7 FortiGates · Limitations note · Checked 2026-10-02
- 26When one fragment of a SIP-over-UDP INVITE is dropped, the receiver never gets the INVITE, so the caller sees only its own retransmissions and then a timeout rather than an error response from the far end.inferredRFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines (fragment-loss behaviour) · Checked 2026-10-02
- 27Kamailio's pmtu_discovery core parameter set to 1 sets the don't-fragment bit on outbound IP packets, and it defaults to 0.Kamailio Core Cookbook (devel) · Core parameters: pmtu_discovery · Checked 2026-10-02
- 28Kamailio core parameters udp_mtu and udp_mtu_try_proto let the proxy send a message over another protocol such as TCP when it would exceed the configured UDP MTU.Kamailio Core Cookbook (devel) · Core parameters: udp_mtu and udp_mtu_try_proto · Checked 2026-10-02
- 29PAN-OS global counters for fragments include flow_ipfrag_recv, flow_ipfrag_merge and flow_ipfrag_frag, plus flow_fwd_ip_df for packets dropped because DF was set and MTU was exceeded.How does the Palo Alto Networks Firewall Manage Fragmented Traffic? · Global counters list · Checked 2026-10-02
- 30Palo Alto Networks firewalls reassemble fragmented traffic for content inspection only and then forward it fragmented according to the egress interface MTU.How does the Palo Alto Networks Firewall Manage Fragmented Traffic? · Resolution section · Checked 2026-10-02
- 31In PJSIP 2.12.1, PJSIP_DONT_SWITCH_TO_TCP defaults to 0, so automatic UDP-to-TCP switching is on, and it can be changed at runtime through disable_tcp_switch in pjsip_cfg_t.Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation · PJSIP_DONT_SWITCH_TO_TCP · Checked 2026-10-02
- 32In PJSIP 2.12.1, PJSIP_UDP_SIZE_THRESHOLD defaults to 1300 bytes, and requests larger than it are sent over TCP when TCP switching is enabled.Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation · PJSIP_UDP_SIZE_THRESHOLD · Checked 2026-10-02
- 33Cisco's BroadWorks note states Polycom phones can be set to TCPOnly, TCPpreferred or DNSnaptr transport so large SIP messages avoid UDP.Working with large SIP packets · Endpoints and SBCs section · Checked 2026-10-02
- 34RFC 3261 states the 1300-byte figure for unknown path MTU is based on assuming a 1500-byte Ethernet MTU.RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, rationale paragraph · Checked 2026-10-02
- 35RFC 3261 requires a SIP request to be sent over an RFC 2914 congestion-controlled transport such as TCP if it is within 200 bytes of the path MTU, or larger than 1300 bytes when the path MTU is unknown.RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, message-size paragraph · Checked 2026-10-02
- 36RFC 3261 explains the 200-byte margin below path MTU as allowance for SIP responses being larger than requests, for example because Record-Route values are added to responses to INVITE.RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, rationale paragraph following the 1300-byte rule · Checked 2026-10-02
- 37RFC 3261 gives the purpose of the size-based switch to a congestion-controlled transport as preventing fragmentation of SIP messages over UDP and providing congestion control for larger messages.RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, sentence following the 1300-byte rule · Checked 2026-10-02
- 38RFC 3261 requires all SIP elements to implement both UDP and TCP.RFC 3261 — SIP: Session Initiation Protocol · Section 18 Transport, introductory paragraphs · Checked 2026-10-02
- 39RFC 4459 says PMTUD signalling for tunnels is unreliable in IPv4 because firewalls and other boxes are often configured to drop all ICMP.RFC 4459: MTU and Fragmentation Issues with In-the-Network Tunneling · Section 3.2 · Checked 2026-10-02
- 40RFC 4459 describes how tunnelling (IP-in-IP, GRE, L2TP, IPsec) adds encapsulation headers, so a source must size packets to fit the smallest MTU on the path after encapsulation.RFC 4459: MTU and Fragmentation Issues with In-the-Network Tunneling · Section 1 Introduction · Checked 2026-10-02
- 41For UDP applications that cannot discover path MTU, RFC 8085 gives the effective send MTU as the smaller of 576 bytes and the first-hop MTU for IPv4, and 1280 bytes for IPv6.RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
- 42RFC 8085 notes that losing a single IP fragment loses the whole reassembled datagram, and that NATs and firewalls may discard fragments.RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
- 43RFC 8085 (BCP 145) says applications SHOULD NOT send UDP datagrams that result in IP packets exceeding the MTU along the path.RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
- 44RFC 8085 recommends PMTUD or Packetization Layer PMTUD for UDP applications, noting that PLPMTUD avoids depending on ICMP messages that middleboxes often filter.RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
- 45RFC 8900 cites a measurement in which at least 28% of sampled paths did not convey packets containing the IPv6 Fragment extension header.RFC 8900: IP Fragmentation Considered Fragile · Section 3.9 · Checked 2026-10-02
- 46RFC 8900 states that NAT devices must virtually reassemble fragmented packets in order to translate and forward each fragment.RFC 8900: IP Fragmentation Considered Fragile · Section 3.3 · Checked 2026-10-02
- 47RFC 8900 says network operators MUST NOT filter ICMPv6 Packet Too Big messages unless they are known to be forged.RFC 8900: IP Fragmentation Considered Fragile · Section 6.5 · Checked 2026-10-02
- 48RFC 8900 (BCP 230, September 2020) says developers SHOULD NOT develop new protocols or applications that rely on IP fragmentation.RFC 8900: IP Fragmentation Considered Fragile · Section 6.1 · Checked 2026-10-02
- 49RFC 8900 explains that persistent loss of ICMP Packet Too Big messages causes persistent path MTU black holes.RFC 8900: IP Fragmentation Considered Fragile · Section 3.8 · Checked 2026-10-02
- 50RFC 8900 notes that non-initial IP fragments carry no transport-layer port information, so a stateless firewall must either accept all subsequent fragments or block them, possibly blocking legitimate traffic.RFC 8900: IP Fragmentation Considered Fragile · Section 3.4 · Checked 2026-10-02
- 51SonicWall documents that SonicOS 5.8 and later drops fragmented SIP over UDP, logging 242 Packet dropped - failed processing.Some or all VoIP (SIP) invites are being dropped due to "242 Packet dropped - failed processing" · Cause section · Checked 2026-10-02
- 52SonicWall's fix for dropped fragmented INVITEs is to shrink SIP messages below MTU by removing unnecessary headers, or to move signalling to SIP over TCP.Some or all VoIP (SIP) invites are being dropped due to "242 Packet dropped - failed processing" · Resolution section · Checked 2026-10-02
- 53In the SonicWall case, calls from external sources worked while some internal calls failed, because only the larger internal INVITEs were fragmented.Some or all VoIP (SIP) invites are being dropped due to "242 Packet dropped - failed processing" · Symptom section · Checked 2026-10-02
- 54Moving SIP signalling from UDP to TCP or TLS removes dependence on IP fragmentation for large messages because TCP segments data to the negotiated MSS, which is why vendors give it as the primary fix.inferredWorking with large SIP packets · Solution section · Checked 2026-10-02
- 55Microsoft Teams Direct Routing signalling is SIP over TLS, with the SBC connecting to the Microsoft SIP proxy on port 5061; no UDP signalling option is listed.Plan Direct Routing · SIP signaling ports table · Checked 2026-10-02
Documents
RFC 3261 — SIP: Session Initiation Protocol
RFC 4459: MTU and Fragmentation Issues with In-the-Network Tunneling
RFC 8085: UDP Usage Guidelines
RFC 8900: IP Fragmentation Considered Fragile
Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0
Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation
How does the Palo Alto Networks Firewall Manage Fragmented Traffic?
Kamailio Core Cookbook (devel)
PJSIP Transport Selection - Asterisk Documentation
Plan Direct Routing
Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec
Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup
Some or all VoIP (SIP) invites are being dropped due to "242 Packet dropped - failed processing"
Technical Tip: Fragmented UDP packets with payload sizes in 1636-1722 byte range may be dropped
Technical Tip: How to Identify UDP NTurbo fragmentation drops and how to resolve them on NP7 FortiGates
Working with large SIP packets
configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch)
SIP and UDP Fragmentation
SIP UDP fragmentation and Kamailio: the SIP header diet
Cite this page
APA
WarmTransfer. (2026, October 2). Troubleshooting failed calls caused by large SIP messages over UDP. WarmTransfer. https://warmtransfer.net/knowledge/sip-fragmentation-troubleshooting
BibTeX
@misc{warmtransfer-sip-fragmentation-troubleshooting,
title = {Troubleshooting failed calls caused by large SIP messages over UDP},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sip-fragmentation-troubleshooting},
note = {Verified 2026-10-02}
}