IKE_AUTH exchanges that carry large certificate chains often exceed the path MTU, and many firewalls and NAT devices discard the resulting IP fragments. IKEv2 fragmentation splits the payload at the IKE layer before IP fragmentation occurs, so each message is small enough to traverse the path intact.