• Cisco Security Cloud Control Management: Cloud-Delivered Firewall Management Center
  • Onboard Devices to Cloud-Delivered Firewall Management Center
  • System Settings
  • Optimize Firewall Performance with AgenticOps
  • Simplify Firewall Operations with Agent Workforce
  • Health and Monitoring
  • Tools
  • Reporting and Alerting
  • Event and Asset Analysis Tools
  • Events and Assets
  • High Availability and Scalability
    • Multi-Instance Mode
    • Logical Devices on the Firepower 4100/9300
    • High Availability for Devices
    • Clustering: Secure Firewall 3100/4200/6100
      • Clustering for the Secure Firewall 3100/4200/6100
      • Licenses for clustering
      • Prerequisites for clustering
      • Guidelines for clustering
      • Clustering configuration
        • Cluster interfaces
          • Cluster control link
            • Cluster control link traffic
            • Cluster control link interfaces and network
            • Size the cluster control link
            • Cluster control link MTU ping testing
            • Cluster control link redundancy
            • Cluster control link reliability for inter-chassis clustering
          • Spanned EtherChannels (Recommended)
          • Individual interfaces
        • Cable and add devices to the Cloud-Delivered Firewall Management Center
        • Create a Cluster
        • Configure interfaces
        • Configure cluster health monitor settings
        • Configure distributed Site-to-Site VPN
      • Cluster node management
      • Monitor the cluster
      • Troubleshoot the cluster
      • Clustering examples
      • Reference for Clustering
      • History for Clustering
    • Clustering: Private Cloud
    • Clustering: Public Cloud
    • Clustering: Firepower 4100/9300
  • Interfaces and Device Settings
  • Routing
  • Network Policies
  • Secure Connections
  • Zero Trust Network Access
  • Access Control Policy Basics
  • Decryption Policies and Encrypted Visibility for Access Control
  • Identity Policies for Access Control
  • Advanced Policies and Settings for Access Control
  • Custom Intrusion Policies for Access Control
  • Objects and Certificates
  • Reference

Cluster control link MTU ping testing

Use Cluster control link MTU ping testing to

  • verify MTU compatibility between cluster nodes during the join process

  • use ping-based fragmentation tests to confirm the network path supports proper packet handling, and

  • allow nodes to join even if tests fail while providing diagnostic messages for troubleshooting MTU mismatches.

Control node ping test

When a node joins the cluster, the control node sends a ping with a payload size of twice the MTU. This process tests the network's ability to handle packet fragmentation because the underlying IP layer will fragment packets that exceed the MTU limit.

A successful ping confirms that the network path supports proper fragmentation and that the cluster control link can reliably process traffic at the configured MTU size.

If the ping fails, view these messages:

  • show cluster history —Event: CCL MTU test to unit name failed

  • Console WARNING—WARNING: Unit name is not reachable in CCL jumbo frame ICMP test, please check cluster interface and switch MTU configuration

Even if the ping fails, the node is allowed to join the cluster. In this case, you need to resolve the MTU mismatch as soon as possible.

Data node ping test

When a node joins the cluster, the joining node checks MTU compatibility by sending a ping to the control node with a packet size matching the cluster control link MTU. If the initial ping fails, the node tries a ping using a smaller packet size (the MTU divided by 2, then by 4, then by 8) until a ping succeeds.

If the ping fails, view these messages:

  • show cluster info trace —Warning: CCL MTU is configured to cfg_mtu_size. However CCL MTU test to unit name failed with size larger_test_size (passed with size smaller_test_size). Please check switch MTU configuration.

    To easily view this WARNING, filter on the show output using show cluster info trace | incl MTU .

  • show cluster history , Cloud-Delivered Firewall Management Center notification—Warning: MTU mismatch detected on the CCL interface. Please ensure that the MTU setting on the connected switch matches the firewall's configured MTU (cfg_mtu_size).

  • Console WARNING—WARNING: Unit name is not reachable in CCL jumbo frame ICMP test, please check cluster interface and switch MTU configuration

Even if the ping fails, the node is allowed to join the cluster. In this case, you need to resolve the MTU mismatch as soon as possible.

Copyright © 2026, Cisco Systems, Inc. All rights reserved.