• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to change MTU/MSSFIX values for OpenVPN in pfsense?

Scheduled Pinned Locked Moved OpenVPN
8 Posts 5 Posters 14.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Techneau
    last edited by Nov 16, 2019, 7:48 AM

    Can anyone explain how to change the MTU/MSSFIX values in pfsense for Openvpn? Please! This have been driving me up the wall. You would think after all these users that made changes to these values on OpenVPN on pfSense you would find a solution but no, not one person, everyone just mention "oh that solved my problem" but it's not helping anyone else. When I try using the shell command in pfsense I get weird message like I must specify tun/tap and when I try to define tun I am told the argument is wrong. If anyone help me with this i will make a simple video for future users with issues. I've been using pfSense since 2011. This is the first time a solution to a problem I have can't be found.!

    Image 003 2019 11 16.png

    Thank you,
    Tech Neau

    1 Reply Last reply Reply Quote 0
    • N
      NogBadTheBad
      last edited by NogBadTheBad Nov 16, 2019, 12:15 PM Nov 16, 2019, 8:16 AM

      Try:-

      VPN -> OpenVPN -> Clients Server -> Edit -> Custom options

      Screenshot 2019-11-16 at 08.15.59.png

      1 Reply Last reply Reply Quote 2
      • T
        Techneau
        last edited by Techneau Nov 20, 2019, 11:50 AM Nov 16, 2019, 8:57 AM

        @NogBadTheBad
        You have got to be kidding me!!! lol, that most definitely worked. I been having issues accessing our VPN thru sprint's cellular network and only from sprint. This is due to recent changes to sprint's network or so a few of us think. In my case since I am using freeRADIUS for user authentication; I don't really have individual client files therefore, I had to add those arguments to the "Additional configuration options" section on the client export page and on the server side, I reset the VPN server and just like that I was able to connect using the cellular network. It has almost been a year since we've logged in thru the cellular network. What's weird tho was the fact we were able to access the VPN thru sprint's hotspot but not cellular. Thanks a million and since we used pictures to show the area for the custom options I don't think we need a video. Nevertheless, I will mention in a upcoming OpenVPN video I will be remaking. Hopes this helps everyone else.

        A million thanks!!

        Image 004 2019 11 16.png

        1 Reply Last reply Reply Quote 0
        • N
          NogBadTheBad
          last edited by Nov 16, 2019, 12:15 PM

          Ah your doing it on the server, I only run OpenVPN as a client.

          Good to hear its working.

          S 1 Reply Last reply Feb 13, 2020, 12:18 AM Reply Quote 0
          • S
            stanzapaticky @NogBadTheBad
            last edited by stanzapaticky Feb 29, 2020, 9:30 AM Feb 13, 2020, 12:18 AM

            @NogBadTheBad Working great for me here in Canada! Rogers updated their modem firmware this week and tunnels had been disconnecting every few minutes. They sent a tech on-site, he made a few phone calls, and told me to try changing the tunnel MTU to 1300. Everything is working great again.
            Capture.PNG

            J 1 Reply Last reply Apr 21, 2020, 8:28 AM Reply Quote 0
            • J
              joshun @stanzapaticky
              last edited by Apr 21, 2020, 8:28 AM

              @stanzapaticky Why do fragment & mssfix differ by 40 bytes?

              N 1 Reply Last reply Apr 21, 2020, 9:47 AM Reply Quote 0
              • N
                NogBadTheBad @joshun
                last edited by Apr 21, 2020, 9:47 AM

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • J
                  JonathanLee
                  last edited by Jun 28, 2024, 5:45 AM

                  https://redmine.pfsense.org/issues/15585

                  Shouldn’t this export creation file include an option to customize the MTU and MSS ?

                  I opened a feature request for this, as I was wondering this today and referenced this thread. Please let me know if this is something you would like to see.

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    [[user:consent.lead]]
                    [[user:consent.not_received]]