Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

MTU question

I have a 1750 running IPSec to a VPN3030.

I am using ping -s 2000 <IP> to send packets, using tcpdump I see that two packets without the DF flag set are sent.

The first packet size is 1500 the second is smaller, I don't get a reply.

Because the DF flag is not set no ICMP is generated.

I have figured out the actual mtu is 1434 for this setup. How do I solve this problem?

2 REPLIES
Green

Re: MTU question

Set your devices for a 1434 MTU.

Encryption does not allow for fragmentation.

What problem are you trying to solve?

Scott

Bronze

Re: MTU question

Hi.

You have to setup MTU 1434 size in both side.

this may be help you out.

-Minu

192
Views
0
Helpful
2
Replies
CreatePlease login to create content