Link to home
Start Free TrialLog in
Avatar of First Last
First LastFlag for United States of America

asked on

Change MTU for just one Site-to-Site VPN between ASAs?

Hi -
 
 
I'm setting up a Site-to-Site Cisco VPN between ASA 5510s. I'm being told by the remote site engineer to set the maximum MTU at 1362.
 
Is it possible to set the MTU for one specific site-to-site VPN on my ASA 5510 Security Plus to MTU 1362? I see my interfeces are all set at 1500.

I came across sysopt connection tcpmss "MTU size" but this appears to be for all traffic going through the ASA.
 
If not, would you recommend I setup a subinterface on my inside network router and a subinterface on the ASA with an MTU of 1362 to get around this issue? Then use this subinterface for traffic from my inside network to transverse through prior to hitting the VPN.
 
Thank you.
ASKER CERTIFIED SOLUTION
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Ernie is correct. MTU can only be set on the physical intf's and not sub's. A subinterface will always take the MTU from the physical one.