I am tying to find out if I am running my PIX VPN's as efficiently as possible. Here is the setup:
Our PIX 525 pair terminates about 150 VPNs from customers and sites. Some connections we control both ends (usually an 1811 on the other side). Others are customer controlled. The PIX devices have 2811s before the PE device. Our primary ISP is qwest serving 30Mbps via an MPLS fiber connection.
On the inside interfaces of the PIX is our datacenter switch stack of 3750s. Our servers connect to this switch stack directrly with the routing being handled by the 3750.
On the PIX we have an MTU on the outside and inside interface at 1500. The MSS is set to 1368. On the inside and outside intercace of the pix pre-fragmentation is enabled and DF bit policy is set to copy.
On the edge routers we have an MTU of 1500 on the inside and outside interface.
This is the same for the 3750 stack. The ports have an MTU of 1500 and the vlan has an mtu of 1500.
I am not seeing any fragmentation on the vpn connections, but I am trying to figure out what the optimal setting should be to maximize throughput.
Any thoughts / comments / advise is greatly appreciated.