Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?
« previous
next »
Print
Pages: [
1
]
Author
Topic: IPsec MTU issues - pfsense has advanced MTU settings but not opnsense? (Read 9126 times)
TheLinuxGuy
Newbie
Posts: 42
Karma: 1
IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?
«
on:
May 16, 2021, 10:29:37 am »
I'm having MTU issues (unable to load websites - dell remote management) over the IPsec tunnel. I have lowered the MTU and MSS settings on my LAN but still facing issues - if I reboot the opnsense it will work for a few minutes so it seems some traffic may respect MSS but then stops working.
pfsense seems to have special settings under IPsec for this condition per
https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/advanced.html
other opnsense users seem to have reported the same issue without resolution:
https://forum.opnsense.org/index.php?topic=17881.0
any idea what can be done?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?
«
Reply #1 on:
May 16, 2021, 01:46:57 pm »
Interfaces : LAN : MSS, set to 1300.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
TheLinuxGuy
Newbie
Posts: 42
Karma: 1
Re: IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?
«
Reply #2 on:
May 16, 2021, 02:14:14 pm »
Quote from: mimugmail on May 16, 2021, 01:46:57 pm
Interfaces : LAN : MSS, set to 1300.
This is exactly what I had configured and was having issues.
I ended up being able to implement a workaround.
Firewall > settings > Normalization
Added a rule:
- Interface "IPsec"
- source any
- dest any
- max MSS set to 1350
Restored LAN to have no MSS. So far its been stable for the past hour and I am uploading a large file.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?
«
Reply #3 on:
May 16, 2021, 04:30:19 pm »
This doesnt makes sense as the IPsec overhead is 40 bytes, so 1300 should be fine
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
IPsec MTU issues - pfsense has advanced MTU settings but not opnsense?