Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    VXLAN over wireguard. Unexpected MTU reset bug(?) (PFSENSE+)

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 2 Posters 595 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      facepunch01
      last edited by

      Environment:

      OS/Software: pfsense+ latest

      Setup: VXLAN over a WireGuard parent interface (VXLAN MTU requires 1370).

      The VXLAN interface is assigned to a bridge.

      The Issue:
      The VXLAN MTU holds at 1370 correctly inside the bridge. However, if I make any change to the WireGuard interface's MTU, the VXLAN interface automatically resets its MTU to 1450 (Visible in Status > interfaces).

      Current Workaround:
      To restore the correct 1370 MTU on the VXLAN interface, I have to completely remove the VXLAN interface from the bridge, save the configuration, and then re-add it.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Hmm, resaving the VXLAN doesn't set the MTU again whilst it's still a bridge member? You are setting the VXLAN MTU to 1370 in the assigned interface config I assume?

        F 1 Reply Last reply Reply Quote 0
        • F Offline
          facepunch01 @stephenw10
          last edited by facepunch01

          @stephenw10 Yeah, it doesn't or at least didn't on my server, I can test that again outside of business hours. Yes, I am setting the VXLAN MTU to 1370 in the assigned interface config. No matter what though, it shouldn't be resetting to 1450 because that is not configured anywhere except as a default value

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            What do you have the WireGuard tunnel MTU set to?

            F 1 Reply Last reply Reply Quote 0
            • F Offline
              facepunch01 @stephenw10
              last edited by

              @stephenw10 1420

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Hmm, well that seems like a problem. I wonder if the bridge code is overriding the VXLAN parent. Let me do some tests...

                F 2 Replies Last reply Reply Quote 0
                • F Offline
                  facepunch01 @stephenw10
                  last edited by

                  @stephenw10 VXLAN tunnel does work perfectly fine when the mtu is set up correctly

                  1 Reply Last reply Reply Quote 1
                  • F Offline
                    facepunch01 @stephenw10
                    last edited by facepunch01

                    @stephenw10 it also resets to 1450 on reboot, however I was wrong saving the interface while in bridge does work

                    F 1 Reply Last reply Reply Quote 1
                    • F Offline
                      facepunch01 @facepunch01
                      last edited by

                      @stephenw10 Is there any update on this

                      F 1 Reply Last reply Reply Quote 0
                      • F Offline
                        facepunch01 @facepunch01
                        last edited by

                        I have been waiting for a long time at this point, I use this feature regularly, and it still breaks every so often randomly because the mtu resets. I will submit a bug request soon

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Yeah open a bug report. It's always better to track it that way anyway.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.