strange mtu problem on site to site vpn

Unanswered Question
Sep 4th, 2009


I have a strange problem.

I cant send packets between 1400 and 1480 bytes to a remote site connected through a aes-256_sha vpn tunnel. This is causing alot of connection problems.

when i send those packets a see a log entry "No translation group found for icmp src outside:x.x.x.x dst inside: (type 3, code 4)" is my station i send the packets from and x.x.x.x is the outside ip address of the asa. The x.x.x.x address is used the nat all the outgoing connections

I tried the command crypto ipsec fragmentation before-encryption outside but that didn't helped.

Any ideas?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
be04376 Fri, 09/04/2009 - 09:21


i just used the command crypto ipsecdf-bit clear and now the packets get trough.

not sure why the asa thinks he can't fragment. I didn't set the dont fragment bit i used ping -s 1400 ( and not the -M do option)


This Discussion