sip media · published

Troubleshooting failed calls caused by large SIP messages over UDP

Verified 2026-10-02 · 55 sources · tier 1–5

Also known as large-sip-invite-fragmentation, sip-udp-fragmentation.

Cisco's BroadWorks tech note says routers commonly block fragmented UDP, and RFC 8085 notes that losing a single IP fragment loses the whole reassembled datagram and that NATs and firewalls may discard fragments 5 42. SonicWall and Fortinet each document fragmented UDP being dropped by their devices, and Cisco IOS voice gateways, PJSIP and Kamailio can send oversized SIP messages over TCP instead 51 23 16 32 28.

How large SIP messages break over UDP

RFC 8085 says applications SHOULD NOT send UDP datagrams that result in IP packets exceeding the MTU along the path 43. For UDP applications that cannot discover path MTU, RFC 8085 gives the effective send MTU as the smaller of 576 bytes and the first-hop MTU for IPv4, and as 1280 bytes for IPv6 41. RFC 8900 says developers SHOULD NOT develop new protocols or applications that rely on IP fragmentation 48.

  • Non-initial IP fragments carry no transport-layer port information, so a stateless firewall must either accept all subsequent fragments or block them, possibly blocking legitimate traffic 50.
  • RFC 8900 states that NAT devices must virtually reassemble fragmented packets in order to translate and forward each fragment 46.
  • RFC 8900 cites a measurement in which at least 28% of sampled paths did not convey packets containing the IPv6 Fragment extension header 45.
  • Cisco's BroadWorks tech note says routers commonly block fragmented UDP because they must buffer fragments until the whole message arrives, and attackers can exploit that buffering to exhaust memory 5.

Field reports suggest that IMS headers added by CSCF elements, together with SDP offering AMR and EVS codecs, push INVITEs past 1300 bytes 20.

We infer that when one fragment of a SIP-over-UDP INVITE is dropped, the receiver never gets the INVITE, so the caller sees only its own retransmissions followed by a timeout rather than an error response from the far end 26.

Tunnels and path MTU discovery

RFC 4459 describes how tunnelling (IP-in-IP, GRE, L2TP, IPsec) adds encapsulation headers, so a source must size packets to fit the smallest MTU on the path after encapsulation 40. Cisco states that GRE encapsulation adds 24 bytes to a packet 9. Cisco also states that IPsec adds at least 1 IPv4 header, and that ESP with ESP authentication overhead does not exceed roughly 58 bytes 12. When GRE is combined with IPsec, Cisco recommends setting the GRE tunnel IP MTU to 1400 bytes to absorb both overheads 10.

  • Cisco notes that PMTUD depends on ICMP Destination Unreachable type 3 code 4 messages, and that filters which block all ICMP types break it 11.
  • RFC 4459 says PMTUD signalling for tunnels is unreliable in IPv4 because firewalls and other boxes are often configured to drop all ICMP 39.
  • RFC 8900 explains that persistent loss of ICMP Packet Too Big messages causes persistent path MTU black holes 49.
  • RFC 8900 says network operators MUST NOT filter ICMPv6 Packet Too Big messages unless they are known to be forged 47.

RFC 8085 recommends PMTUD or Packetization Layer PMTUD for UDP applications, and notes that PLPMTUD avoids depending on ICMP messages that middleboxes often filter 44.

Cisco documents that ip tcp adjust-mss works by reducing the MSS value carried in TCP SYN packets 8. WarmTransfer's reading of the sources is that MSS clamping therefore cannot stop a SIP-over-UDP INVITE larger than the tunnel MTU from being fragmented, and that it helps SIP only after signalling moves to TCP or TLS 1.

Diagnosing it

In SonicWall's documented case, calls from external sources worked while some internal calls failed, because only the larger internal INVITEs were fragmented 53. SonicWall documents that SonicOS 5.8 and later drops fragmented SIP over UDP and logs "242 Packet dropped - failed processing" 51.

Fortinet documents that NP7-based FortiGates with an IPS profile may drop fragmented UDP packets with payloads of 1636 to 1722 bytes on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0 23. On NP7 FortiGates, NTurbo fragmentation drops are identified by running diagnose test app ipsmonitor 14 and watching the drop(decode) counter increase 22.

Palo Alto Networks firewalls reassemble fragmented traffic for content inspection only, then forward it fragmented according to the egress interface MTU 30. PAN-OS global counters for fragments include flow_ipfrag_recv, flow_ipfrag_merge and flow_ipfrag_frag, plus flow_fwd_ip_df for packets dropped because DF was set and the MTU was exceeded 29.

Moving signalling to TCP or TLS

WarmTransfer's reading of the sources is that moving SIP signalling from UDP to TCP or TLS removes dependence on IP fragmentation for large messages because TCP segments data to the negotiated MSS, which is why vendors give it as the primary fix 54. In the field, practitioners report that switching SIP to TCP is often impractical, because many peers do not have TCP enabled or reachable, especially behind NAT 21.

Cisco IOS voice gateways and CUBE

  • Dial-peer command: On Cisco IOS voice gateways and CUBE, voice-class sip transport switch udp tcp switches a SIP request from UDP to TCP when the request size exceeds the MTU size 16.
  • Default and release: The command is disabled by default 15. It was introduced in Cisco IOS Release 12.3(8)T 14.
  • Global command: Cisco's command reference also describes a global transport switch command that switches transport for SIP messages larger than 1300 bytes. It states that the dial-peer command takes precedence over the global command 13.

Cisco Unified CM

In a Cisco Unified CM 12.5(1) SIP trunk security profile with Device Security Mode set to Non Secure, the incoming transport type is TCP+UDP, while with Authenticated or Encrypted it is TLS 17. The same 12.5(1) security guide says to use UDP as the SIP trunk outgoing transport only when the far end does not support TCP, and otherwise to use TCP as the default 18.

Cisco BroadWorks and Polycom phones

  • Transport switching: Cisco BroadWorks handles large SIP messages by switching them to TCP rather than relying on UDP fragmentation. Transport can be set to UDP, TCP or unspecified per interface, network server, media server and routing NE 7.
  • Enabling TCP: The Application Server parameter supportTcp under AS_CLI/Interface/SIP enables TCP for SIP 6.
  • Polycom phones: Cisco's BroadWorks note states that Polycom phones can be set to TCPOnly, TCPpreferred or DNSnaptr transport so that large SIP messages avoid UDP 33.

PJSIP and Asterisk

  • PJSIP threshold: In PJSIP 2.12.1, PJSIP_UDP_SIZE_THRESHOLD defaults to 1300 bytes. Requests larger than this are sent over TCP when TCP switching is enabled 32.
  • PJSIP switching default: In PJSIP 2.12.1, PJSIP_DONT_SWITCH_TO_TCP defaults to 0, so automatic UDP-to-TCP switching is on. It can be changed at runtime through disable_tcp_switch in pjsip_cfg_t 31.
  • Asterisk default: In Asterisk res_pjsip, the [system] option disable_tcp_switch defaults to yes. Asterisk therefore does not automatically switch large outgoing requests from UDP to TCP unless configured to 2.
  • Asterisk TCP requirement: Asterisk documentation warns that when the TCP switch is enabled, a large message switched to TCP fails if no TCP transport is configured or the remote side is not listening on TCP 4.
  • Asterisk interoperability: The Asterisk sample pjsip.conf warns that turning off disable_tcp_switch has been known to cause interoperability issues 3.

Kamailio

The Kamailio core parameters udp_mtu and udp_mtu_try_proto let the proxy send a message over another protocol, such as TCP, when it would exceed the configured UDP MTU 28. Setting Kamailio's pmtu_discovery core parameter to 1 sets the don't-fragment bit on outbound IP packets; the parameter defaults to 0 27.

Microsoft Teams Direct Routing

Microsoft Teams Direct Routing signalling is SIP over TLS, with the SBC connecting to the Microsoft SIP proxy on port 5061, and no UDP signalling option is listed 55.

Shrinking messages

SonicWall's fix for dropped fragmented INVITEs is to shrink SIP messages below the MTU by removing unnecessary headers, or to move signalling to SIP over TCP 52.

Field reports suggest that practitioners trimming SIP to avoid UDP fragmentation commonly remove User-Agent or Server, Allow, Date and Timestamp headers and prune unused codecs from the SDP, treating them as low-risk removals 19.

Firewall-side workarounds

Fortinet's workarounds for NP7 fragmented-UDP drops include enabling NPU IP reassembly (config system npu, config ip-reassembly, set status enable), disabling auto-asic-offload on the policy, or removing the IPS sensor 24.

Fortinet states that NP7 IP reassembly handles packets fragmented into at most 2 pieces, and that for 3 or more fragments NTurbo must be disabled 25.

See also

Applicability

Applies to: Cisco BroadWorks, SonicWall SonicOS, Fortinet FortiGate, Cisco Unified Border Element, Teluu PJSIP, Kamailio project, Cisco IOS XE, Palo Alto Networks PAN-OS, Cisco Unified Communications Manager, Poly UC Software, Sangoma Asterisk, and Microsoft Teams Direct Routing. Deployments: on-premises and multi-tenant. Sources checked 2026-10-02. The Cisco IOS voice-class sip transport switch command applies to Cisco IOS Release 12.3(8)T and later, where it was introduced 14. The Cisco Unified CM transport settings described here come from the Release 12.5(1) security guide 18. The PJSIP defaults described here are those of PJSIP 2.12.1 32. The Fortinet fragmented-UDP drop applies to NP7-based FortiGates on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0 23. The SonicWall behaviour is documented for SonicOS 5.8 and later 51.

What remains uncertain

  • SD-WAN: SD-WAN tunnel MTU defaults and their effect on voice fragmentation are not covered by the sources below.
  • SIP specification: The SIP specification's own wording on transport selection and message size is not covered by the sources below.
  • Cisco Unified CM auto-switching: Whether Cisco Unified CM automatically switches oversized SIP messages from UDP to TCP on SIP trunks is not covered by the sources below.
  • CUBE message trimming: CUBE configuration for removing headers and SDP lines to shrink SIP messages is not covered by the sources below.
  • Phone vendor guides: Phone transport settings as documented in phone vendors' own admin guides are not covered by the sources below.
  • Packet capture: A packet-capture method for showing fragments leaving one point on a SIP path and not arriving at another is not covered by the sources below.
  • SIP ALG and reassembly: The interaction between SIP ALG inspection and fragment reassembly on firewalls is not covered by the sources below.
  • Current SonicOS releases: Whether current SonicOS releases still drop fragmented SIP over UDP is not covered by the sources below.

See also

Related to

Referenced by

Sources

  1. 1
    Because MSS clamping rewrites only TCP SYN options, it cannot stop a SIP-over-UDP INVITE larger than the tunnel MTU from being fragmented; it helps SIP only after signalling moves to TCP or TLS.inferred
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · ip tcp adjust-mss section · Checked 2026-10-02
  2. 2
    In Asterisk res_pjsip the [system] option disable_tcp_switch defaults to yes, so Asterisk does not automatically switch large outgoing requests from UDP to TCP unless configured to.
    configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch) · [system] section, disable_tcp_switch comment block · Checked 2026-10-02
  3. 3
    The Asterisk sample pjsip.conf warns that turning off disable_tcp_switch has been known to cause interoperability issues.
    configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch) · [system] section, disable_tcp_switch comment block · Checked 2026-10-02
  4. 4
    Asterisk documentation warns that if the TCP switch is enabled, a large message switched to TCP fails when no TCP transport is configured or the remote side is not listening on TCP.
    PJSIP Transport Selection - Asterisk Documentation · Changeover to TCP when sending via UDP · Checked 2026-10-02
  5. 5
    Cisco's BroadWorks tech note says routers commonly block fragmented UDP because they must buffer fragments until the whole message arrives, which attackers can exploit to exhaust memory.
    Working with large SIP packets · Problem section · Checked 2026-10-02
  6. 6
    In Cisco BroadWorks, the Application Server parameter supportTcp under AS_CLI/Interface/SIP enables TCP for SIP.
    Working with large SIP packets · Solution section, AS_CLI/Interface/SIP · Checked 2026-10-02
  7. 7
    Cisco BroadWorks handles large SIP messages by switching them to TCP rather than relying on UDP fragmentation, with transport settable per interface, network server, media server and routing NE as UDP, TCP or unspecified.
    Working with large SIP packets · Solution section · Checked 2026-10-02
  8. 8
    Cisco documents that ip tcp adjust-mss works by reducing the MSS value carried in TCP SYN packets.
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · ip tcp adjust-mss section · Checked 2026-10-02
  9. 9
    Cisco states that GRE encapsulation adds 24 bytes to a packet.
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE and IPsec overhead discussion · Checked 2026-10-02
  10. 10
    Cisco recommends setting the GRE tunnel IP MTU to 1400 bytes when GRE is combined with IPsec, to absorb both overheads.
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE over IPsec recommendations · Checked 2026-10-02
  11. 11
    Cisco notes that PMTUD depends on ICMP Destination Unreachable type 3 code 4 messages and that filters which block all ICMP types break it.
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · PMTUD and ICMP filtering section · Checked 2026-10-02
  12. 12
    Cisco states that IPsec adds at least one IPv4 header and that ESP with ESP authentication overhead does not exceed roughly 58 bytes.
    Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec · GRE and IPsec overhead discussion · Checked 2026-10-02
  13. 13
    Cisco's command reference describes a global transport switch command that switches transport for SIP messages larger than 1300 bytes, and states the dial-peer voice-class sip transport switch command takes precedence over it.
    Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Usage Guidelines and Related Commands table · Checked 2026-10-02
  14. 14
    The voice-class sip transport switch command was introduced in Cisco IOS Release 12.3(8)T.
    Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Command History · Checked 2026-10-02
  15. 15
    The voice-class sip transport switch dial-peer command is disabled by default.
    Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Command Default · Checked 2026-10-02
  16. 16
    On Cisco IOS voice gateways and CUBE, the dial-peer command voice-class sip transport switch udp tcp switches a SIP request from UDP to TCP when the request size exceeds the MTU size.
    Cisco IOS Voice Command Reference - T through Z - voice-class sip error-code-override through vxml version 2.0 · voice-class sip transport switch: Syntax Description · Checked 2026-10-02
  17. 17
    In a Cisco Unified CM 12.5(1) SIP trunk security profile with Device Security Mode Non Secure, the incoming transport type is TCP+UDP; with Authenticated or Encrypted it is TLS.
    Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup · Table 1 SIP Trunk Security Profile Configuration Settings, Incoming Transport Type · Checked 2026-10-02
  18. 18
    Cisco's Unified CM 12.5(1) security guide says to use UDP as the SIP trunk outgoing transport only when the far end does not support TCP, and otherwise to use TCP as the default.
    Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup · Table 1 SIP Trunk Security Profile Configuration Settings, Outgoing Transport Type note · Checked 2026-10-02
  19. 19
    Practitioners trimming SIP to avoid UDP fragmentation commonly remove User-Agent or Server, Allow, Date and Timestamp headers and prune unused codecs from SDP, treating them as low-risk removals.field report
    SIP UDP fragmentation and Kamailio: the SIP header diet · Section listing safe header removals · Checked 2026-10-02
  20. 20
    Practitioners report that IMS headers added by CSCF elements and SDP offering AMR and EVS codecs push INVITEs past 1300 bytes.field report
    SIP and UDP Fragmentation · Root causes discussion · Checked 2026-10-02
  21. 21
    Practitioners report that switching SIP to TCP is often impractical in the field because many peers do not have TCP enabled or reachable, especially behind NAT.field report
    SIP UDP fragmentation and Kamailio: the SIP header diet · Discussion of TCP as alternative · Checked 2026-10-02
  22. 22
    On NP7 FortiGates, NTurbo fragmentation drops are identified with diagnose test app ipsmonitor 14 by watching the drop(decode) counter increase.
  23. 23
    Fortinet documents that NP7-based FortiGates with an IPS profile may drop fragmented UDP packets with payloads of 1636 to 1722 bytes on FortiOS releases before 7.4.10, 7.6.5 or 8.0.0.
  24. 24
    Fortinet's workarounds for NP7 fragmented-UDP drops include enabling NPU IP reassembly (config system npu, config ip-reassembly, set status enable), disabling auto-asic-offload on the policy, or removing the IPS sensor.
  25. 25
    Fortinet states NP7 IP reassembly handles packets fragmented into at most two pieces; for three or more fragments NTurbo must be disabled.
  26. 26
    When one fragment of a SIP-over-UDP INVITE is dropped, the receiver never gets the INVITE, so the caller sees only its own retransmissions and then a timeout rather than an error response from the far end.inferred
    RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines (fragment-loss behaviour) · Checked 2026-10-02
  27. 27
    Kamailio's pmtu_discovery core parameter set to 1 sets the don't-fragment bit on outbound IP packets, and it defaults to 0.
    Kamailio Core Cookbook (devel) · Core parameters: pmtu_discovery · Checked 2026-10-02
  28. 28
    Kamailio core parameters udp_mtu and udp_mtu_try_proto let the proxy send a message over another protocol such as TCP when it would exceed the configured UDP MTU.
    Kamailio Core Cookbook (devel) · Core parameters: udp_mtu and udp_mtu_try_proto · Checked 2026-10-02
  29. 29
    PAN-OS global counters for fragments include flow_ipfrag_recv, flow_ipfrag_merge and flow_ipfrag_frag, plus flow_fwd_ip_df for packets dropped because DF was set and MTU was exceeded.
    How does the Palo Alto Networks Firewall Manage Fragmented Traffic? · Global counters list · Checked 2026-10-02
  30. 30
    Palo Alto Networks firewalls reassemble fragmented traffic for content inspection only and then forward it fragmented according to the egress interface MTU.
  31. 31
    In PJSIP 2.12.1, PJSIP_DONT_SWITCH_TO_TCP defaults to 0, so automatic UDP-to-TCP switching is on, and it can be changed at runtime through disable_tcp_switch in pjsip_cfg_t.
    Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation · PJSIP_DONT_SWITCH_TO_TCP · Checked 2026-10-02
  32. 32
    In PJSIP 2.12.1, PJSIP_UDP_SIZE_THRESHOLD defaults to 1300 bytes, and requests larger than it are sent over TCP when TCP switching is enabled.
    Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation · PJSIP_UDP_SIZE_THRESHOLD · Checked 2026-10-02
  33. 33
    Cisco's BroadWorks note states Polycom phones can be set to TCPOnly, TCPpreferred or DNSnaptr transport so large SIP messages avoid UDP.
    Working with large SIP packets · Endpoints and SBCs section · Checked 2026-10-02
  34. 34
    RFC 3261 states the 1300-byte figure for unknown path MTU is based on assuming a 1500-byte Ethernet MTU.
    RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, rationale paragraph · Checked 2026-10-02
  35. 35
    RFC 3261 requires a SIP request to be sent over an RFC 2914 congestion-controlled transport such as TCP if it is within 200 bytes of the path MTU, or larger than 1300 bytes when the path MTU is unknown.
    RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, message-size paragraph · Checked 2026-10-02
  36. 36
    RFC 3261 explains the 200-byte margin below path MTU as allowance for SIP responses being larger than requests, for example because Record-Route values are added to responses to INVITE.
    RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, rationale paragraph following the 1300-byte rule · Checked 2026-10-02
  37. 37
    RFC 3261 gives the purpose of the size-based switch to a congestion-controlled transport as preventing fragmentation of SIP messages over UDP and providing congestion control for larger messages.
    RFC 3261 — SIP: Session Initiation Protocol · Section 18.1.1 Sending Requests, sentence following the 1300-byte rule · Checked 2026-10-02
  38. 38
    RFC 3261 requires all SIP elements to implement both UDP and TCP.
    RFC 3261 — SIP: Session Initiation Protocol · Section 18 Transport, introductory paragraphs · Checked 2026-10-02
  39. 39
    RFC 4459 says PMTUD signalling for tunnels is unreliable in IPv4 because firewalls and other boxes are often configured to drop all ICMP.
  40. 40
    RFC 4459 describes how tunnelling (IP-in-IP, GRE, L2TP, IPsec) adds encapsulation headers, so a source must size packets to fit the smallest MTU on the path after encapsulation.
    RFC 4459: MTU and Fragmentation Issues with In-the-Network Tunneling · Section 1 Introduction · Checked 2026-10-02
  41. 41
    For UDP applications that cannot discover path MTU, RFC 8085 gives the effective send MTU as the smaller of 576 bytes and the first-hop MTU for IPv4, and 1280 bytes for IPv6.
    RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
  42. 42
    RFC 8085 notes that losing a single IP fragment loses the whole reassembled datagram, and that NATs and firewalls may discard fragments.
    RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
  43. 43
    RFC 8085 (BCP 145) says applications SHOULD NOT send UDP datagrams that result in IP packets exceeding the MTU along the path.
    RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
  44. 44
    RFC 8085 recommends PMTUD or Packetization Layer PMTUD for UDP applications, noting that PLPMTUD avoids depending on ICMP messages that middleboxes often filter.
    RFC 8085: UDP Usage Guidelines · Section 3.2 Message Size Guidelines · Checked 2026-10-02
  45. 45
    RFC 8900 cites a measurement in which at least 28% of sampled paths did not convey packets containing the IPv6 Fragment extension header.
    RFC 8900: IP Fragmentation Considered Fragile · Section 3.9 · Checked 2026-10-02
  46. 46
    RFC 8900 states that NAT devices must virtually reassemble fragmented packets in order to translate and forward each fragment.
    RFC 8900: IP Fragmentation Considered Fragile · Section 3.3 · Checked 2026-10-02
  47. 47
    RFC 8900 says network operators MUST NOT filter ICMPv6 Packet Too Big messages unless they are known to be forged.
    RFC 8900: IP Fragmentation Considered Fragile · Section 6.5 · Checked 2026-10-02
  48. 48
    RFC 8900 (BCP 230, September 2020) says developers SHOULD NOT develop new protocols or applications that rely on IP fragmentation.
    RFC 8900: IP Fragmentation Considered Fragile · Section 6.1 · Checked 2026-10-02
  49. 49
    RFC 8900 explains that persistent loss of ICMP Packet Too Big messages causes persistent path MTU black holes.
    RFC 8900: IP Fragmentation Considered Fragile · Section 3.8 · Checked 2026-10-02
  50. 50
    RFC 8900 notes that non-initial IP fragments carry no transport-layer port information, so a stateless firewall must either accept all subsequent fragments or block them, possibly blocking legitimate traffic.
    RFC 8900: IP Fragmentation Considered Fragile · Section 3.4 · Checked 2026-10-02
  51. 51
    SonicWall documents that SonicOS 5.8 and later drops fragmented SIP over UDP, logging 242 Packet dropped - failed processing.
  52. 52
    SonicWall's fix for dropped fragmented INVITEs is to shrink SIP messages below MTU by removing unnecessary headers, or to move signalling to SIP over TCP.
  53. 53
    In the SonicWall case, calls from external sources worked while some internal calls failed, because only the larger internal INVITEs were fragmented.
  54. 54
    Moving SIP signalling from UDP to TCP or TLS removes dependence on IP fragmentation for large messages because TCP segments data to the negotiated MSS, which is why vendors give it as the primary fix.inferred
    Working with large SIP packets · Solution section · Checked 2026-10-02
  55. 55
    Microsoft Teams Direct Routing signalling is SIP over TLS, with the SBC connecting to the Microsoft SIP proxy on port 5061; no UDP signalling option is listed.
    Plan Direct Routing · SIP signaling ports table · Checked 2026-10-02

Documents

tier 1 standards and regulators

RFC 3261 — SIP: Session Initiation Protocol

IETF / RFC Editor · 2002-06 · accessed 2026-09-04

tier 1 standards and regulators

RFC 4459: MTU and Fragmentation Issues with In-the-Network Tunneling

RFC Editor (IETF) · 2006-04-01 · accessed 2026-10-02

tier 1 standards and regulators

RFC 8085: UDP Usage Guidelines

RFC Editor (IETF) · 2017-03-01 · accessed 2026-10-02

tier 1 standards and regulators

RFC 8900: IP Fragmentation Considered Fragile

RFC Editor (IETF) · 2020-09-01 · accessed 2026-10-02

tier 2 current vendor documentation

Group PJSIP_CONFIG - PJSIP Project 2.12.1 documentation

PJSIP project (Teluu) · accessed 2026-10-02

tier 2 current vendor documentation

How does the Palo Alto Networks Firewall Manage Fragmented Traffic?

Palo Alto Networks · 2024-11-20 · accessed 2026-10-02

tier 2 current vendor documentation

Kamailio Core Cookbook (devel)

Kamailio project · accessed 2026-10-02

tier 2 current vendor documentation

PJSIP Transport Selection - Asterisk Documentation

Sangoma / Asterisk project · accessed 2026-10-02

tier 2 current vendor documentation

Plan Direct Routing

Microsoft (Microsoft Learn) · 2026-08-21 · accessed 2026-09-06

tier 2 current vendor documentation

Resolve IPv4 Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPsec

Cisco Systems · 2023-05-17 · accessed 2026-10-02

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 12.5(1) - SIP Trunk Security Profile Setup

Cisco Systems · 2025-02-24 · accessed 2026-10-02

tier 2 current vendor documentation

Some or all VoIP (SIP) invites are being dropped due to "242 Packet dropped - failed processing"

SonicWall · 2020-03-26 · accessed 2026-10-02

tier 2 current vendor documentation

Technical Tip: Fragmented UDP packets with payload sizes in 1636-1722 byte range may be dropped

Fortinet · 2026-01-16 · accessed 2026-10-02

tier 2 current vendor documentation

Technical Tip: How to Identify UDP NTurbo fragmentation drops and how to resolve them on NP7 FortiGates

Fortinet · 2024-05-15 · accessed 2026-10-02

tier 2 current vendor documentation

Working with large SIP packets

Cisco Systems · 2020-11-11 · accessed 2026-10-02

tier 3 vendor-maintained repositories

configs/samples/pjsip.conf.sample (asterisk/asterisk, master branch)

Sangoma / Asterisk project · accessed 2026-10-02

tier 5 independent technical research

SIP and UDP Fragmentation

Cloud Telco Hub (Hossein Yavari) · 2023-03-17 · accessed 2026-10-02

tier 5 independent technical research

SIP UDP fragmentation and Kamailio: the SIP header diet

Evariste Systems (Alex Balashov) · 2016-02-04 · accessed 2026-10-02

Cite this page

APA

WarmTransfer. (2026, October 2). Troubleshooting failed calls caused by large SIP messages over UDP. WarmTransfer. https://warmtransfer.net/knowledge/sip-fragmentation-troubleshooting

BibTeX

@misc{warmtransfer-sip-fragmentation-troubleshooting,
  title  = {Troubleshooting failed calls caused by large SIP messages over UDP},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/sip-fragmentation-troubleshooting},
  note   = {Verified 2026-10-02}
}