cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
569
Views
15
Helpful
3
Replies

Changing MTU to resolve an IPSEC tunnel that won't establish?

CiscoPurpleBelt
Level 6
Level 6

I know many times you must change the MTU to less than the default otherwise certain Aps, sites, etc. the traverse the tunnel have poor performance, but are there instances where MTU could play a part in just establishing Ikev1 tunnels between two routers? 

Don't have the debugs right (to verify where it is failing or what errors seen) here but all parameters are the same on both ends, keys, etc., IPSEC negotiation traffic makes it to both ends, wondering if MTU could play a part just on tunnel negotiations.

 

2 Accepted Solutions

Accepted Solutions

Deepak Kumar
VIP Alumni
VIP Alumni

Hi,

I have never seen that MTU could cause of negotiation issue. Yes, I faced slowness or some of the services not working issue due to MTU. I would like to check logs and configuration.

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

View solution in original post

I can not think of a circumstance where MTU would prevent ISAKMP negotiation. It really would be helpful to see the debug output.

HTH

Rick

View solution in original post

3 Replies 3

Deepak Kumar
VIP Alumni
VIP Alumni

Hi,

I have never seen that MTU could cause of negotiation issue. Yes, I faced slowness or some of the services not working issue due to MTU. I would like to check logs and configuration.

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

I can not think of a circumstance where MTU would prevent ISAKMP negotiation. It really would be helpful to see the debug output.

HTH

Rick

Yes that is what I thought, had to make sure.

Too challenging to post on here, I can't even get to the remote site in any fashion LOL.

 

Thanks again!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card