GRE/IPSec Tunnel Help!!!

Unanswered Question
Sep 30th, 2009
User Badges:

We have some routers that are going over a GRE tunnel and have IPSec encryption. THis is done over a 3G line. We were experiencing problems with certain applications being slow and changed the mtu size from 1514 to 1420. This improved the connection to our applications but now they are having issues getting to certain internet sites. Has anyone seen this issue before? Is there a fix to it?

This is our tunnel config...

interface Tunnel0

ip address

ip tcp adjust-mss 1420

tunnel source Cellular0/1/0

tunnel destination

tunnel path-mtu-discovery


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Peter Paluch Wed, 09/30/2009 - 09:07
User Badges:
  • Cisco Employee,


Can you be more specific about the "issues getting to certain internet sites"? Do you suspect your packets getting lost? Is the connection still slow? Can you perhaps identify some technical issue that you believe to be related to the cause of your problem?

Best regards,


Brent Rockburn Wed, 09/30/2009 - 09:25
User Badges:

ip tcp adjust-mss 1360

On the Cellular0/1/0 interface.

I had a similar issue and this helped.

Giuseppe Larosa Thu, 10/01/2009 - 07:35
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

Hello Dennis,

I agree with Brent you need to reduce further TCP MSS 1420 doesn't reflect all your encapsulation overheads (GRE 24 Bytes and IPSEC (variable depending if using tunnel mode or not) and 40 bytes IPv4 + TCP headers)

Hope to help



This Discussion