If you want to enable MSS clamping on all IPSEC VPN tunnels, then, am I right, you set it here:
Firewall: Settings: Normalization
And, under detailed settings, you can then make a specific rule to enable MSS clamping on the IPSEC interface.
New "Firewall scrub rule"
Select Interface "IPSEC"
Max mss "1400"
See my screenshot.
Is that correct?
Is that all I need to do?