Hi, as per this document when DF bit is set to clear, it allows router to fragment the packets. http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dplane/configuration/15-mt/sec-ipsec-data-plane-15-mt-book/sec-df-bit-ovride.html The clear key...