MTU issues in crypto map tunnel connections


A strange issue at work has come up so it’s back to the drawing board… i mean GNS3 🙂

The problem is that user cannot connect to an application. It seems that the application sends packets that are too large for the path MTU. After some research, it seems that this problem is described in scenario 8 from the following document.

Long story short, PMTUD will break if ‚no ip unreachables’ is configured anywhere on the path or if some firewall blocks ICMP. One workaround is to actually clear DF bit on the crypto map entry with ‚set security-association df bit clear’ command.
GNS3 testing shows that this should work but whether the application will like it is a different story.


