We have a 5506-x that we recently upgraded to 9.16.2 and then 9.16.3 but then had to revert back to 9.12.4 because of a long-standing bug that's been around since 9.14 that was supposedly fixed but isn't. We ended up reverting back to the initial 9.12.4, but we're now having a problem now where packets under 990B are dropped over the site-to-site VPN tunnel if the do not fragment bit is set. This is running the same configuration as before. There is no problem with the larger packets to the Internet. We have several dozen VPN tunnels connected to the same headend, which are not having a problem. I'm not sure where to look next, so any thoughts what I might check? The interface MTUs are set to 1500B.
mtu outside 1500
mtu inside 1500
Thank you.