Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    MTU size on IPsec tunnel…

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 7.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sup3rior
      last edited by

      Have a setup where on the remote endpoints require a max MTU size of 1350 to work properly.

      Been reading up a bit on this and it would seem enabling "MSS clamping on VPN traffic" is the right way to go about this.
      But I cannot figure out if this will have any impact on all the other tunnels that are running through this pfSense box, and whether the setting is replicated through CARP or must be set on all nodes?

      Hope someone can point me in the right direction…

      //Anders

      1 Reply Last reply Reply Quote 1
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It would affect all tunnels, and it would not replicate via carp as it's a per-host setting.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • S
          Sup3rior
          last edited by

          @jimp:

          It would affect all tunnels, and it would not replicate via carp as it's a per-host setting.

          Got so far as to figure out it was a system-wide setting, but since I'm not that strong on network I'm trying to figure out whether it will have any negative effect on the other tunnels or if alle other VPN endpoints should adjust their MTU size when communicating with the pfSense boxes…

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.