IPSec MTU issue

Started by rhaker, June 30, 2020, 11:18:18 AM

Previous topic - Next topic
Hello all,

I'm having an issue with a tunnel that seems to be MTU related.
Currently site A and site B are connected via Cisco hardware, everything works.
When I replace Site A with OPNSense the tunnel works, I can access certain devices on site B, but not everything works.
When checking MTU over the Cisco tunnel it gives me 1452 but via OPNSense it gives me 1500, irregardless of interface settings at either site A or B.
To test I have introduced site C to the mix, which can connect to site A via OPNSense but has the same problem to site B.
I suspect MSS clamping isn't working correctly for IPsec traffic.