cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
488
Views
0
Helpful
1
Replies

Site to site VPN MTU reco

Tod Larson
Level 3
Level 3

We are going to deploy a site to site VPN using two ASA5505. The network I'm going to traverse has a max MTU of 1320. I determined this by experimenting with pings of different sizes.

How should I configure MTU on my ASAs?

I'm thinking of using these two commands but I don't know if there are any implications to this...

ip mtu outside 1320

ip mtu inside 1280

Any comments are appreciated.

1 Accepted Solution

Accepted Solutions

Eugene Khabarov
Level 7
Level 7

You don't need to change interfaces MTU itself. But be aware that you need allow ICMP traffic to make PMTUD mechanism works. So your correct mtu setting will be agreed over remote hosts that acts over VPN.

HTH. Please rate if it was helpful. Thank you.

View solution in original post

1 Reply 1

Eugene Khabarov
Level 7
Level 7

You don't need to change interfaces MTU itself. But be aware that you need allow ICMP traffic to make PMTUD mechanism works. So your correct mtu setting will be agreed over remote hosts that acts over VPN.

HTH. Please rate if it was helpful. Thank you.