Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Fragment Handling (IPsec VPN)

I have numerous working IPSec VPNs on a PIX 515E. Once of those works a bit slow. The engineer at the remote end changed his MTU size to handle the outbound fragmentation and the performance increased a little. He wants me to change my side as well. But I do not want to impact any of the other tunnels by changing the Global MTU size settings which is 1500. Is it possible to set a different MTU size for a specific tunnel on my pix? My PIX 515E Firewall Version is 6.3(1)

1 REPLY
Silver

Re: Fragment Handling (IPsec VPN)

AFAIK it is possible to change the MTU on a per interface basis and not possible on a per tunnel basis. You could probably subinterface the PIX, create a DMZ and route this specific VPN through the DMZ.

110
Views
2
Helpful
1
Replies
CreatePlease login to create content