Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC VTI Interface neighbor MTU 1500 is larger then ipsec2000´s MTU 1400

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 552 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pete35
      last edited by

      I have some IPSEC VTI Tunnels up and running, after a restart, one of the vti interfaces comes up with the wrong MTU size settings.

      Feb 12 15:55:21 ospfd 77445 Packet[DD]: Neighbor 10.1.44.101 MTU 1500 is larger than [ipsec2000:10.1.99.1]'s MTU 1400

      After digging in i saved the settings of the smaller VTI Interface and everythings starts working again.

      But: at both sites the MTU is set to 1500 ... so it shouldnt resize it to 1400 at startup ....

      2140392d-b32e-4e7b-9cf2-02d7c5939db7-image.png

      <a href="https://carsonlam.ca">bintang88</a>
      <a href="https://carsonlam.ca">slot88</a>

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        https://redmine.pfsense.org/issues/9111 (Fixed in 2.4.5)

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • P
          pete35
          last edited by

          Thank you, one of the boxes which im waiting for the release.... and dont want to update top early...

          <a href="https://carsonlam.ca">bintang88</a>
          <a href="https://carsonlam.ca">slot88</a>

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            You can install the System Patches package and then create an entry for affe8a552ef1f7b8e59f3b60fd1421aa46f45b03 to apply the fix. It's a fairly small change and should be safe.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • P
              pete35
              last edited by

              @jimp said in IPSEC VTI Interface neighbor MTU 1500 is larger then ipsec2000´s MTU 1400:

              affe8a552ef1f7b8e59f3b60fd1421aa46f45b03

              Done. Thank you.

              <a href="https://carsonlam.ca">bintang88</a>
              <a href="https://carsonlam.ca">slot88</a>

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.