ASA5520 with AnyConnect VPN Client MTU size

Unanswered Question
Jan 5th, 2009

Hi All,

I have a ASA5520 installed with the AnyConnect VPN Client setup. Noticed that the maximum mtu size is 1406 bytes inside the tunnel.

Would like to know if this is normal behavior for ASA? Can we adjust the mtu size to let say 1472 or 1500 bytes?

With that, will the VPN users experience any applications difficulty because of the smaller mtu size?

Thanks & Regards,

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Ivan Martinon Fri, 01/09/2009 - 16:58

Usually a lower MTU helps due to the fact that VPN, whatever the protocol adds overhead to normal traffic, setting lower MTU allows traffic to be fragmented which helps with performance, I have seen more cases where it helps than where it harms. You can change the MTU of the AnnyConnect client with the SVC MTU command under the group policy setup

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1410844

Actions

This Discussion