Mtu fragmentation issue may raise due to progression of Denial of service attack. Too many IP fragments are currently awaiting reassembly. By default, the maximum number of fragments is 200. The security appliance limits the number of IP fragments that can be concurrently reassembled. This restriction prevents memory depletion at the security appliance under abnormal network conditions. In general, fragmented traffic should be a small percentage of the total traffic mix. An exception is in a network environment with NFS over UDP where a large percentage is fragmented traffic; if this type of traffic is relayed through the security appliance, consider using NFS over TCP instead. To prevent fragmentation, see the sysopt connection tcpmss bytes command here
http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/s8.html#wp1381654