Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
In L2L VPN over internet, MTU will be smaller than default 1500 bytes. Because of that SSL handshake can fail because of the Don't Fragment flag set in IPv4 header.
In this case I would either allowed and enabled ICMP Unreachable (recommended) or cle...