<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MTU Size issue? in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595463#M365373</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="test.jpg" style="width: 773px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149348iEADFC867207470B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="test.jpg" alt="test.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks more like this. Sorry, i'm unable to get any config files as of yet due to the nature of the system.&lt;/P&gt;&lt;P&gt;I would gladly look up anything you have questions about.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Apr 2022 14:26:03 GMT</pubDate>
    <dc:creator>KGrev</dc:creator>
    <dc:date>2022-04-19T14:26:03Z</dc:date>
    <item>
      <title>MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595447#M365370</link>
      <description>&lt;P&gt;Hi, I'm trying to resolve an issue im having with a vpn connection to a mobile LTE Router (IR 809G)&lt;/P&gt;&lt;P&gt;Normally the connection and throughput is fine, however i'm being required at add an encryption device to one router to form a link to another encryption device inside out network.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Throughput of lte routers normally = many megs&lt;/LI&gt;&lt;LI&gt;throughput through encryption device through lte router = 56k hard lock&lt;/LI&gt;&lt;LI&gt;throughput of encryption devices connected to switch = 100meg&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm wondering if im having an mtu issue pushing a tunnel through a vpn on the lte router.&lt;/P&gt;&lt;P&gt;When I send a ping with df-bit from LTE router (not through encryptor device) it begins to fragment at 1439.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Router vpn terminates to an ASA also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've dropped the mtu on the encryption devices well below this but have not noticed a change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595447#M365370</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T14:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595451#M365371</link>
      <description>&lt;P&gt;Can you provide a rough diagram or running configuration of the devices? I don't think we have enough information here to give any good advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming your topology looks like - VPN SPOKE &amp;gt; INLINE ENCRYPTOR &amp;gt; INLINE ENCRYPTOR &amp;gt; VPN HUB&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595451#M365371</guid>
      <dc:creator>jamesduv9</dc:creator>
      <dc:date>2022-04-19T14:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595457#M365372</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the interface configs on both sides along with any logs you get as it pertains to the fragmentation? If you're going through a tunnel and encryption you may need to reduce it more along with the tcp-mss. See below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;int &amp;lt;int#&amp;gt;&lt;/P&gt;&lt;P&gt;mtu 1400&lt;/P&gt;&lt;P&gt;ip tcp&amp;nbsp; adjust-mss 1360 &amp;lt;- should be 40 less than mtu as good practice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-David&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595457#M365372</guid>
      <dc:creator>David Ruess</dc:creator>
      <dc:date>2022-04-19T14:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595463#M365373</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="test.jpg" style="width: 773px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149348iEADFC867207470B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="test.jpg" alt="test.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks more like this. Sorry, i'm unable to get any config files as of yet due to the nature of the system.&lt;/P&gt;&lt;P&gt;I would gladly look up anything you have questions about.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595463#M365373</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T14:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595474#M365375</link>
      <description>&lt;P&gt;So, nothing so far has reported that there is a fragmentation issue.&lt;/P&gt;&lt;P&gt;The encryptor devices may be having the issue but their logging is pretty empty.&lt;/P&gt;&lt;P&gt;For adjusting the tcp-mss, ive been experimenting in a few different places on where to add that but unsure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The LTE router has:&lt;/P&gt;&lt;P&gt;G0 - encryptor device port&lt;/P&gt;&lt;P&gt;Virtual-access2&amp;nbsp; -&amp;nbsp; the template for the vpn&lt;/P&gt;&lt;P&gt;Cellular 0 - the interface it sends to cellular&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can add tcp-mss adjust to each of those or set mtu to a certain size. Unsure which one would need it.&lt;/P&gt;&lt;P&gt;By default the Virtual-access2 mtu says its around 17000, which is interesting. I assume thats something like a virtual link inside the router?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can adjust the group policy for the vpn at the ASA and change mtu size.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595474#M365375</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T14:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595477#M365376</link>
      <description>&lt;P&gt;Thanks for the diagram. You should also be able to set the MTU size on the encryptor itself. I would refer to the vendors documentation on how much overhead is required, and subtract that from your LTE router's tunnel MTU. I believe a popular INE vendor suggests 50 bytes.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595477#M365376</guid>
      <dc:creator>jamesduv9</dc:creator>
      <dc:date>2022-04-19T14:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595481#M365378</link>
      <description>&lt;P&gt;Config for LTE Router&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 19109 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 14:24:33 UTC Tue Apr 19 2022 by local_login&lt;BR /&gt;!&lt;BR /&gt;version 15.8&lt;BR /&gt;no service pad&lt;BR /&gt;service tcp-keepalives-in&lt;BR /&gt;service tcp-keepalives-out&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;service internal&lt;BR /&gt;service sequence-numbers&lt;BR /&gt;no service dhcp&lt;BR /&gt;!&lt;BR /&gt;hostname CS016-PRB1&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;security passwords min-length 10&lt;BR /&gt;enable secret 5 XXXXXXX&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ABC-RADIUS&lt;BR /&gt;server name I-NPS-01&lt;BR /&gt;server name I-NPS-02&lt;BR /&gt;ip radius source-interface Loopback0&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login ABC-AUTH group ABC-RADIUS local&lt;BR /&gt;aaa authentication enable default enable&lt;BR /&gt;aaa authorization exec ABC-AUTHO group ABC-RADIUS local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip source-route&lt;BR /&gt;no ip gratuitous-arps&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip bootp server&lt;BR /&gt;ip domain lookup source-interface Loopback0&lt;BR /&gt;ip domain name ABCis.local&lt;BR /&gt;ip name-server X.Y..219.10&lt;BR /&gt;ip name-server X.Y..219.11&lt;BR /&gt;ip inspect WAAS flush-timeout 10&lt;BR /&gt;ip cef&lt;BR /&gt;login block-for 60 attempts 5 within 60&lt;BR /&gt;login on-failure log&lt;BR /&gt;login on-success log&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;chat-script lte "" "AT!CALL" TIMEOUT 20 "OK"&lt;BR /&gt;password encryption aes&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint ABC_NET_Trust&lt;BR /&gt;enrollment terminal&lt;BR /&gt;serial-number&lt;BR /&gt;ip-address loopback0&lt;BR /&gt;revocation-check crl&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;*************CRYPTO******************&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt;log config&lt;BR /&gt;record rc&lt;BR /&gt;logging enable&lt;BR /&gt;logging size 500&lt;BR /&gt;notify syslog contenttype plaintext&lt;BR /&gt;hidekeys&lt;BR /&gt;object-group network IA-ADMIN-ADDRESS&lt;BR /&gt;description IP addresses of IA admin boxes&lt;BR /&gt;host X.X2.231&lt;BR /&gt;host X.X2.232&lt;BR /&gt;host X.X2.235&lt;BR /&gt;host X.X2.96&lt;BR /&gt;!&lt;BR /&gt;object-group service IPSLA-SERVICES&lt;BR /&gt;description Ports used for IPSLA testing&lt;BR /&gt;udp eq 1967&lt;BR /&gt;udp eq 17000&lt;BR /&gt;!&lt;BR /&gt;object-group service IPv6_TRAFFIC_FILTER_NET_TUNL_001&lt;BR /&gt;description Ports used in outdated tunneling schemes&lt;BR /&gt;42&lt;BR /&gt;93&lt;BR /&gt;nos&lt;BR /&gt;97&lt;BR /&gt;98&lt;BR /&gt;udp eq 1723&lt;BR /&gt;tcp eq 1723&lt;BR /&gt;60&lt;BR /&gt;!&lt;BR /&gt;object-group network MANAGEMENT-ADDRESSES&lt;BR /&gt;description IP ranges of management devices&lt;BR /&gt;X.X242.0 255.255.255.0&lt;BR /&gt;X.X243.0 255.255.255.0&lt;BR /&gt;X.X102.0 255.255.255.0&lt;BR /&gt;host X.X0.114&lt;BR /&gt;host 10.200.252.101&lt;BR /&gt;X.Y..219.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;object-group service MANAGEMENT-SERVICES&lt;BR /&gt;description Ports used for network management&lt;BR /&gt;udp eq snmp&lt;BR /&gt;tcp eq 22&lt;BR /&gt;icmp&lt;BR /&gt;udp eq syslog&lt;BR /&gt;!&lt;BR /&gt;object-group network NTP-SERVERS&lt;BR /&gt;description IP Addresses of NTP servers&lt;BR /&gt;host X.X102.5&lt;BR /&gt;host X.X102.6&lt;BR /&gt;!&lt;BR /&gt;object-group network RADIUS-SERVERS&lt;BR /&gt;description IP Address of radius servers&lt;BR /&gt;host X.Y..219.10&lt;BR /&gt;host X.Y..219.11&lt;BR /&gt;!&lt;BR /&gt;object-group service RADIUS-SERVICES&lt;BR /&gt;description Ports used for radius servers&lt;BR /&gt;udp eq 1645&lt;BR /&gt;udp eq 1646&lt;BR /&gt;!&lt;BR /&gt;object-group service VPN-SERVICES&lt;BR /&gt;description VPN traffic&lt;BR /&gt;udp eq isakmp&lt;BR /&gt;esp&lt;BR /&gt;!&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;************USERNAMES*******************&lt;BR /&gt;!&lt;BR /&gt;redundancy&lt;BR /&gt;notification-timer 120000&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;controller Cellular 0&lt;BR /&gt;lte sim fast-switchover enable&lt;BR /&gt;lte failovertimer 5&lt;BR /&gt;no cdp run&lt;BR /&gt;!&lt;BR /&gt;ip tcp synwait-time 10&lt;BR /&gt;!&lt;BR /&gt;class-map match-all CoPP_UNDESIRABLE&lt;BR /&gt;match access-group name CoPP_UNDESIRABLE&lt;BR /&gt;class-map match-any CoPP_IMPORTANT&lt;BR /&gt;match access-group name CoPP_IMPORTANT&lt;BR /&gt;match protocol arp&lt;BR /&gt;class-map match-all CoPP_DEFAULT&lt;BR /&gt;match access-group name CoPP_DEFAULT&lt;BR /&gt;class-map match-all CoPP_NORMAL&lt;BR /&gt;match access-group name CoPP_NORMAL&lt;BR /&gt;class-map match-all CoPP_CRITICAL&lt;BR /&gt;match access-group name CoPP_CRITICAL&lt;BR /&gt;!&lt;BR /&gt;policy-map CONTROL_PLANE_POLICY&lt;BR /&gt;class CoPP_CRITICAL&lt;BR /&gt;police 512000 8000 conform-action transmit exceed-action transmit&lt;BR /&gt;class CoPP_IMPORTANT&lt;BR /&gt;police 512000 4000 conform-action transmit exceed-action drop&lt;BR /&gt;class CoPP_NORMAL&lt;BR /&gt;police 128000 2000 conform-action transmit exceed-action drop&lt;BR /&gt;class CoPP_UNDESIRABLE&lt;BR /&gt;police 8000 1000 conform-action drop exceed-action drop&lt;BR /&gt;class CoPP_DEFAULT&lt;BR /&gt;police 64000 1000 conform-action transmit exceed-action drop&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 1&lt;BR /&gt;encr aes 256&lt;BR /&gt;authentication pre-share&lt;BR /&gt;group 2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE&lt;BR /&gt;connect auto&lt;BR /&gt;group RMCS_BitProbe key 6 QM[D[\gLHEfSPVTgQaYgICbAZOEAAB&lt;BR /&gt;mode network-extension&lt;BR /&gt;peer X.X0.114&lt;BR /&gt;virtual-interface 2&lt;BR /&gt;username rmcsprobe-sec password 6 _dcZM^A^YFLQ`HKfALOAgPRP\faV[O^XAK_ZI]iIgYAAB&lt;BR /&gt;xauth userid mode local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Loopback0&lt;BR /&gt;ip address X.X9.32 255.255.255.254&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;ip flow ingress&lt;BR /&gt;ip flow egress&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE inside&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0&lt;BR /&gt;ip address X.X244.1 255.255.255.252&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;no cdp enable&lt;BR /&gt;no keepalive&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE inside&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt;no ip address&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;no cdp enable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2&lt;BR /&gt;no ip address&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt;ip address negotiated&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;encapsulation slip&lt;BR /&gt;dialer in-band&lt;BR /&gt;dialer idle-timeout 0&lt;BR /&gt;dialer string lte&lt;BR /&gt;dialer watch-group 1&lt;BR /&gt;async mode interactive&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE&lt;BR /&gt;!&lt;BR /&gt;interface Cellular1&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation slip&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Virtual-Template2 type tunnel&lt;BR /&gt;ip unnumbered Cellular0&lt;BR /&gt;ip access-group ACL-INFRASTRUCTURE-IN in&lt;BR /&gt;ip access-group ACL-INFRASTRUCTURE-OUT out&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;!&lt;BR /&gt;interface Async0&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation scada&lt;BR /&gt;!&lt;BR /&gt;interface Async1&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation scada&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;!&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;ip http client source-interface Loopback0&lt;BR /&gt;ip flow-export source Loopback0&lt;BR /&gt;ip flow-export version 5&lt;BR /&gt;ip flow-export destination X.Y..219.41 2055&lt;BR /&gt;!&lt;BR /&gt;ip ftp source-interface Loopback0&lt;BR /&gt;ip tftp source-interface Loopback0&lt;BR /&gt;ip route X.X0.114 255.255.255.255 Cellular0&lt;BR /&gt;ip ssh time-out 60&lt;BR /&gt;ip ssh version 2&lt;BR /&gt;ip ssh server algorithm mac hmac-sha1 hmac-sha1-96&lt;BR /&gt;ip ssh server algorithm encryption aes128-cbc aes192-cbc aes256-cbc&lt;BR /&gt;ip scp server enable&lt;BR /&gt;!&lt;BR /&gt;******************ACLs********************&lt;BR /&gt;!&lt;BR /&gt;ip radius source-interface Loopback0&lt;BR /&gt;ip sla responder&lt;BR /&gt;ip sla 10&lt;BR /&gt;icmp-echo X.Y..219.41 source-interface Loopback0&lt;BR /&gt;threshold 2000&lt;BR /&gt;frequency 30&lt;BR /&gt;ip sla enable reaction-alerts&lt;BR /&gt;logging facility local2&lt;BR /&gt;logging source-interface Loopback0&lt;BR /&gt;logging host X.Y..219.31&lt;BR /&gt;dialer watch-list 1 ip 5.6.7.8 0.0.0.0&lt;BR /&gt;dialer watch-list 1 delay route-check initial 60&lt;BR /&gt;dialer watch-list 1 delay connect 1&lt;BR /&gt;ipv6 ioam timestamp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;************SNMP**************************&lt;/P&gt;&lt;P&gt;radius server I-NPS-01&lt;BR /&gt;address ipv4 X.Y..219.10 auth-port 1645 acct-port 1646&lt;BR /&gt;key 6 NYUDHbXaIJWb`NaTHVei^RBi^HhSHIbTGVMRdeOfcaaJDFcXEMMAAB&lt;BR /&gt;!&lt;BR /&gt;radius server I-NPS-02&lt;BR /&gt;address ipv4 X.Y..219.11 auth-port 1645 acct-port 1646&lt;BR /&gt;key 6 ^Id_MA`IAWIc]BWBMhgfNSHWKZ`gL^ODNBYaLB[]G\^JOBiZK]VAAB&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;service-policy input CONTROL_PLANE_POLICY&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;banner login ^CCCC&lt;BR /&gt;********************BANNER**************&lt;BR /&gt;^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;exec-timeout 5 0&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication ABC-AUTH&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 1&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 2&lt;BR /&gt;no activation-character&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport input ssh&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 3&lt;BR /&gt;exec-timeout 0 0&lt;BR /&gt;script dialer lte&lt;BR /&gt;modem InOut&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;rxspeed 100000000&lt;BR /&gt;txspeed 50000000&lt;BR /&gt;line 8&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;rxspeed 100000000&lt;BR /&gt;txspeed 50000000&lt;BR /&gt;line 1/3 1/6&lt;BR /&gt;transport preferred none&lt;BR /&gt;transport output none&lt;BR /&gt;stopbits 1&lt;BR /&gt;line vty 0 4&lt;BR /&gt;access-class Mgmt_Access in&lt;BR /&gt;exec-timeout 5 0&lt;BR /&gt;authorization exec ABC-AUTHO&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication ABC-AUTH&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;!&lt;BR /&gt;no scheduler max-task-time&lt;BR /&gt;ntp authentication-key 1 md5 011012075218494E117E6B5B 7&lt;BR /&gt;ntp authenticate&lt;BR /&gt;ntp trusted-key 1&lt;BR /&gt;ntp source Loopback0&lt;BR /&gt;ntp access-group peer NTP-SERVERS&lt;BR /&gt;ntp update-calendar&lt;BR /&gt;ntp server X.X102.5 key 1&lt;BR /&gt;ntp server X.X102.6 key 1 prefer&lt;BR /&gt;no iox hdm-enable&lt;BR /&gt;iox client enable interface GigabitEthernet2&lt;BR /&gt;no iox recovery-enable&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595481#M365378</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T14:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595506#M365380</link>
      <description>&lt;P&gt;LTE Router Config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 19109 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 14:24:33 UTC Tue Apr 19 2022 by local_login&lt;BR /&gt;!&lt;BR /&gt;version 15.8&lt;BR /&gt;no service pad&lt;BR /&gt;service tcp-keepalives-in&lt;BR /&gt;service tcp-keepalives-out&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;service internal&lt;BR /&gt;service sequence-numbers&lt;BR /&gt;no service dhcp&lt;BR /&gt;!&lt;BR /&gt;hostname CS016-PRB1&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;security passwords min-length 10&lt;BR /&gt;enable secret 5 XXXXXXX&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ABC-RADIUS&lt;BR /&gt;server name I-NPS-01&lt;BR /&gt;server name I-NPS-02&lt;BR /&gt;ip radius source-interface Loopback0&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login ABC-AUTH group ABC-RADIUS local&lt;BR /&gt;aaa authentication enable default enable&lt;BR /&gt;aaa authorization exec ABC-AUTHO group ABC-RADIUS local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip source-route&lt;BR /&gt;no ip gratuitous-arps&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip bootp server&lt;BR /&gt;ip domain lookup source-interface Loopback0&lt;BR /&gt;ip domain name ABCis.local&lt;BR /&gt;ip name-server X.Y..219.10&lt;BR /&gt;ip name-server X.Y..219.11&lt;BR /&gt;ip inspect WAAS flush-timeout 10&lt;BR /&gt;ip cef&lt;BR /&gt;login block-for 60 attempts 5 within 60&lt;BR /&gt;login on-failure log&lt;BR /&gt;login on-success log&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;chat-script lte "" "AT!CALL" TIMEOUT 20 "OK"&lt;BR /&gt;password encryption aes&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint ABC_NET_Trust&lt;BR /&gt;enrollment terminal&lt;BR /&gt;serial-number&lt;BR /&gt;ip-address loopback0&lt;BR /&gt;revocation-check crl&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;*************CRYPTO******************&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt;log config&lt;BR /&gt;record rc&lt;BR /&gt;logging enable&lt;BR /&gt;logging size 500&lt;BR /&gt;notify syslog contenttype plaintext&lt;BR /&gt;hidekeys&lt;BR /&gt;object-group network IA-ADMIN-ADDRESS&lt;BR /&gt;description IP addresses of IA admin boxes&lt;BR /&gt;host X.X2.231&lt;BR /&gt;host X.X2.232&lt;BR /&gt;host X.X2.235&lt;BR /&gt;host X.X2.96&lt;BR /&gt;!&lt;BR /&gt;object-group service IPSLA-SERVICES&lt;BR /&gt;description Ports used for IPSLA testing&lt;BR /&gt;udp eq 1967&lt;BR /&gt;udp eq 17000&lt;BR /&gt;!&lt;BR /&gt;object-group service IPv6_TRAFFIC_FILTER_NET_TUNL_001&lt;BR /&gt;description Ports used in outdated tunneling schemes&lt;BR /&gt;42&lt;BR /&gt;93&lt;BR /&gt;nos&lt;BR /&gt;97&lt;BR /&gt;98&lt;BR /&gt;udp eq 1723&lt;BR /&gt;tcp eq 1723&lt;BR /&gt;60&lt;BR /&gt;!&lt;BR /&gt;object-group network MANAGEMENT-ADDRESSES&lt;BR /&gt;description IP ranges of management devices&lt;BR /&gt;X.X242.0 255.255.255.0&lt;BR /&gt;X.X243.0 255.255.255.0&lt;BR /&gt;X.X102.0 255.255.255.0&lt;BR /&gt;host X.X0.114&lt;BR /&gt;host 10.200.252.101&lt;BR /&gt;X.Y..219.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;object-group service MANAGEMENT-SERVICES&lt;BR /&gt;description Ports used for network management&lt;BR /&gt;udp eq snmp&lt;BR /&gt;tcp eq 22&lt;BR /&gt;icmp&lt;BR /&gt;udp eq syslog&lt;BR /&gt;!&lt;BR /&gt;object-group network NTP-SERVERS&lt;BR /&gt;description IP Addresses of NTP servers&lt;BR /&gt;host X.X102.5&lt;BR /&gt;host X.X102.6&lt;BR /&gt;!&lt;BR /&gt;object-group network RADIUS-SERVERS&lt;BR /&gt;description IP Address of radius servers&lt;BR /&gt;host X.Y..219.10&lt;BR /&gt;host X.Y..219.11&lt;BR /&gt;!&lt;BR /&gt;object-group service RADIUS-SERVICES&lt;BR /&gt;description Ports used for radius servers&lt;BR /&gt;udp eq 1645&lt;BR /&gt;udp eq 1646&lt;BR /&gt;!&lt;BR /&gt;object-group service VPN-SERVICES&lt;BR /&gt;description VPN traffic&lt;BR /&gt;udp eq isakmp&lt;BR /&gt;esp&lt;BR /&gt;!&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;************USERNAMES*******************&lt;BR /&gt;!&lt;BR /&gt;redundancy&lt;BR /&gt;notification-timer 120000&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;controller Cellular 0&lt;BR /&gt;lte sim fast-switchover enable&lt;BR /&gt;lte failovertimer 5&lt;BR /&gt;no cdp run&lt;BR /&gt;!&lt;BR /&gt;ip tcp synwait-time 10&lt;BR /&gt;!&lt;BR /&gt;class-map match-all CoPP_UNDESIRABLE&lt;BR /&gt;match access-group name CoPP_UNDESIRABLE&lt;BR /&gt;class-map match-any CoPP_IMPORTANT&lt;BR /&gt;match access-group name CoPP_IMPORTANT&lt;BR /&gt;match protocol arp&lt;BR /&gt;class-map match-all CoPP_DEFAULT&lt;BR /&gt;match access-group name CoPP_DEFAULT&lt;BR /&gt;class-map match-all CoPP_NORMAL&lt;BR /&gt;match access-group name CoPP_NORMAL&lt;BR /&gt;class-map match-all CoPP_CRITICAL&lt;BR /&gt;match access-group name CoPP_CRITICAL&lt;BR /&gt;!&lt;BR /&gt;policy-map CONTROL_PLANE_POLICY&lt;BR /&gt;class CoPP_CRITICAL&lt;BR /&gt;police 512000 8000 conform-action transmit exceed-action transmit&lt;BR /&gt;class CoPP_IMPORTANT&lt;BR /&gt;police 512000 4000 conform-action transmit exceed-action drop&lt;BR /&gt;class CoPP_NORMAL&lt;BR /&gt;police 128000 2000 conform-action transmit exceed-action drop&lt;BR /&gt;class CoPP_UNDESIRABLE&lt;BR /&gt;police 8000 1000 conform-action drop exceed-action drop&lt;BR /&gt;class CoPP_DEFAULT&lt;BR /&gt;police 64000 1000 conform-action transmit exceed-action drop&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 1&lt;BR /&gt;encr aes 256&lt;BR /&gt;authentication pre-share&lt;BR /&gt;group 2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE&lt;BR /&gt;connect auto&lt;BR /&gt;group RMCS_BitProbe key 6 QM[D[\gLHEfSPVTgQaYgICbAZOEAAB&lt;BR /&gt;mode network-extension&lt;BR /&gt;peer X.X0.114&lt;BR /&gt;virtual-interface 2&lt;BR /&gt;username rmcsprobe-sec password 6 _dcZM^A^YFLQ`HKfALOAgPRP\faV[O^XAK_ZI]iIgYAAB&lt;BR /&gt;xauth userid mode local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Loopback0&lt;BR /&gt;ip address X.X9.32 255.255.255.254&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;ip flow ingress&lt;BR /&gt;ip flow egress&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE inside&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0&lt;BR /&gt;ip address X.X244.1 255.255.255.252&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;no cdp enable&lt;BR /&gt;no keepalive&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE inside&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt;no ip address&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;no cdp enable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2&lt;BR /&gt;no ip address&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt;ip address negotiated&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;encapsulation slip&lt;BR /&gt;dialer in-band&lt;BR /&gt;dialer idle-timeout 0&lt;BR /&gt;dialer string lte&lt;BR /&gt;dialer watch-group 1&lt;BR /&gt;async mode interactive&lt;BR /&gt;crypto ipsec client ezvpn RMCSPROBE&lt;BR /&gt;!&lt;BR /&gt;interface Cellular1&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation slip&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Virtual-Template2 type tunnel&lt;BR /&gt;ip unnumbered Cellular0&lt;BR /&gt;ip access-group ACL-INFRASTRUCTURE-IN in&lt;BR /&gt;ip access-group ACL-INFRASTRUCTURE-OUT out&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;!&lt;BR /&gt;interface Async0&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation scada&lt;BR /&gt;!&lt;BR /&gt;interface Async1&lt;BR /&gt;no ip address&lt;BR /&gt;encapsulation scada&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;!&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;ip http client source-interface Loopback0&lt;BR /&gt;ip flow-export source Loopback0&lt;BR /&gt;ip flow-export version 5&lt;BR /&gt;ip flow-export destination X.Y..219.41 2055&lt;BR /&gt;!&lt;BR /&gt;ip ftp source-interface Loopback0&lt;BR /&gt;ip tftp source-interface Loopback0&lt;BR /&gt;ip route X.X0.114 255.255.255.255 Cellular0&lt;BR /&gt;ip ssh time-out 60&lt;BR /&gt;ip ssh version 2&lt;BR /&gt;ip ssh server algorithm mac hmac-sha1 hmac-sha1-96&lt;BR /&gt;ip ssh server algorithm encryption aes128-cbc aes192-cbc aes256-cbc&lt;BR /&gt;ip scp server enable&lt;BR /&gt;!&lt;BR /&gt;******************ACLs********************&lt;BR /&gt;!&lt;BR /&gt;ip radius source-interface Loopback0&lt;BR /&gt;ip sla responder&lt;BR /&gt;ip sla 10&lt;BR /&gt;icmp-echo X.Y..219.41 source-interface Loopback0&lt;BR /&gt;threshold 2000&lt;BR /&gt;frequency 30&lt;BR /&gt;ip sla enable reaction-alerts&lt;BR /&gt;logging facility local2&lt;BR /&gt;logging source-interface Loopback0&lt;BR /&gt;logging host X.Y..219.31&lt;BR /&gt;dialer watch-list 1 ip 5.6.7.8 0.0.0.0&lt;BR /&gt;dialer watch-list 1 delay route-check initial 60&lt;BR /&gt;dialer watch-list 1 delay connect 1&lt;BR /&gt;ipv6 ioam timestamp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;************SNMP**************************&lt;/P&gt;&lt;P&gt;radius server I-NPS-01&lt;BR /&gt;address ipv4 X.Y..219.10 auth-port 1645 acct-port 1646&lt;BR /&gt;key 6 NYUDHbXaIJWb`NaTHVei^RBi^HhSHIbTGVMRdeOfcaaJDFcXEMMAAB&lt;BR /&gt;!&lt;BR /&gt;radius server I-NPS-02&lt;BR /&gt;address ipv4 X.Y..219.11 auth-port 1645 acct-port 1646&lt;BR /&gt;key 6 ^Id_MA`IAWIc]BWBMhgfNSHWKZ`gL^ODNBYaLB[]G\^JOBiZK]VAAB&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;service-policy input CONTROL_PLANE_POLICY&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;banner login ^CCCC&lt;BR /&gt;********************BANNER**************&lt;BR /&gt;^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;exec-timeout 5 0&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication ABC-AUTH&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 1&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 2&lt;BR /&gt;no activation-character&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport input ssh&lt;BR /&gt;stopbits 1&lt;BR /&gt;line 3&lt;BR /&gt;exec-timeout 0 0&lt;BR /&gt;script dialer lte&lt;BR /&gt;modem InOut&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;rxspeed 100000000&lt;BR /&gt;txspeed 50000000&lt;BR /&gt;line 8&lt;BR /&gt;no exec&lt;BR /&gt;transport preferred lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh&lt;BR /&gt;rxspeed 100000000&lt;BR /&gt;txspeed 50000000&lt;BR /&gt;line 1/3 1/6&lt;BR /&gt;transport preferred none&lt;BR /&gt;transport output none&lt;BR /&gt;stopbits 1&lt;BR /&gt;line vty 0 4&lt;BR /&gt;access-class Mgmt_Access in&lt;BR /&gt;exec-timeout 5 0&lt;BR /&gt;authorization exec ABC-AUTHO&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication ABC-AUTH&lt;BR /&gt;transport preferred ssh&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;!&lt;BR /&gt;no scheduler max-task-time&lt;BR /&gt;ntp authentication-key 1 md5 011012075218494E117E6B5B 7&lt;BR /&gt;ntp authenticate&lt;BR /&gt;ntp trusted-key 1&lt;BR /&gt;ntp source Loopback0&lt;BR /&gt;ntp access-group peer NTP-SERVERS&lt;BR /&gt;ntp update-calendar&lt;BR /&gt;ntp server X.X102.5 key 1&lt;BR /&gt;ntp server X.X102.6 key 1 prefer&lt;BR /&gt;no iox hdm-enable&lt;BR /&gt;iox client enable interface GigabitEthernet2&lt;BR /&gt;no iox recovery-enable&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595506#M365380</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T15:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595511#M365381</link>
      <description>&lt;P&gt;(I may be reposting as my post keeps going away)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached LTE Router Config.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595511#M365381</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T15:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595526#M365382</link>
      <description>&lt;P&gt;James, Thank you for your response.&lt;/P&gt;&lt;P&gt;Ive dropped the MTU down on the encryption devices as low as 1300 with no change.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595526#M365382</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T15:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595556#M365385</link>
      <description>&lt;P&gt;Nice draw&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 16:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595556#M365385</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-19T16:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595558#M365386</link>
      <description>&lt;P&gt;Please can You more elaborate about&lt;BR /&gt;LTE-ASA VPN is OK&amp;nbsp;&lt;BR /&gt;Encrypt/Decrypt -LTE-ASA-Encrypt/Decrypt &amp;lt;- here is issue ??&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 16:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595558#M365386</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-19T16:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595593#M365390</link>
      <description>&lt;P&gt;MHM, thank you for your response.&lt;/P&gt;&lt;P&gt;IF I am understanding you correctly, Yes, the LTE router vpn is working ok and normal on its own. I am able to plug a laptop into is and access the inner network and transfer files at expected speeds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only time I'm having the 56K speeds is when I use the encryption devices at each end of the link.&lt;/P&gt;&lt;P&gt;On their own with just a switch between them, they opperate at full speeds. But when I try to use them over the LTE router link, I get the slow speeds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My suspicioun has been that possibly I'm having an mtu problem when I push the tunnel of the encryption devices inside of the vpn the LTE devices use. But I dont have much evidence to support that as of yet. Without the encryption devices, I can send pings without fragmentation at 1438 mtu size. When I lower the mtu of the encryption devices down well below this, there is no change so far. I could be looking in the wrong place.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 17:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595593#M365390</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T17:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595597#M365391</link>
      <description>&lt;P&gt;More information,&lt;/P&gt;&lt;P&gt;Here is a picture from the laptop sending pings till the MTU is too high. It drops of at 1397 while connected to the encryption devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 17:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595597#M365391</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T17:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595601#M365392</link>
      <description>&lt;P&gt;More information,&lt;/P&gt;&lt;P&gt;Here is a picture from the laptop sending pings till the MTU is too high. It drops of at 1397 while connected to the encryption devices.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20220419_122726.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149364i13BAF9569CC8C3AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20220419_122726.jpg" alt="20220419_122726.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 17:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595601#M365392</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T17:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595620#M365393</link>
      <description>&lt;P&gt;So You get the &amp;nbsp;&lt;STRONG&gt;solution&lt;/STRONG&gt;, reduce the MTU to be 1397&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;1439-1397 = 42-44 bytes&lt;/STRONG&gt;&lt;/FONT&gt; and that OK if you use GRE/IPSec or L2TP/IPSec.&lt;/P&gt;&lt;P&gt;note that new header for encrypt vpn add to original data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 17:44:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595620#M365393</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-19T17:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: MTU Size issue?</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595648#M365401</link>
      <description>&lt;P&gt;At which interface should I put this change, I have a few options listed above.&lt;/P&gt;&lt;P&gt;And should I just change the mtu or use tcp-mss adjust instead?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 18:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/mtu-size-issue/m-p/4595648#M365401</guid>
      <dc:creator>KGrev</dc:creator>
      <dc:date>2022-04-19T18:27:53Z</dc:date>
    </item>
  </channel>
</rss>

