Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Changing MTU on IPSEC interface only? Possible?

    Scheduled Pinned Locked Moved General pfSense Questions
    1 Posts 1 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jdamnation
      last edited by

      We have moved to a new firewall system, replacing an old Snapgear unit with a pair of Pfsense boxes. All in all (despite a few weird things) we're very happy.

      However, we suspect we have some MTU fragging going on with the VPN link. For some reason, we didn't have this issue with the Snapgear unit, and we're running the same IPSEC configuration. We have a Hifn card for IPSEC offload.

      We still have a Snapgear at the other end, so I was thinking perhaps this was part of the problem. We are able to manually adjust the MTU of the IPSEC interface on the Snapgear - but we can't seen to do this with pfsense. We can adjust the MTU of the WAN interface, but then almost all of the WAN traffic on this setup is HTTPS - and we are worried about slowing that down by reducing the packet sizes.

      So what we really want to do - is reduce the MTU on the IPSEC interface, but not the WAN interface.

      Possible?

      JD

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.