IT Knowledge Base

User Tools

Site Tools


Contact me at for any feedback or suggestions.

My other sites:

Search all my sites:


This is an old revision of the document!

You can see what the VPN is using for MTU like this:

    cisco#sh int tu0
    Tunnel0 is up, line protocol is up
      Hardware is Tunnel
      Internet address is
      MTU 17912 bytes, BW 100 Kbit/sec, DLY 50000 usec,
         reliability 255/255, txload 17/255, rxload 5/255

Here's my recommended default config for ADSL:

    interface Dialer0
     ip mtu 1492
    interface Tunnel0
     ip mtu 1500
     ip tcp adjust-mss 1400

Some troubleshooting info:

I'd suggest to watch “show ip traffic” and monitor fragmented packet count.

Regarding fergmentation it should be enough to set MSS on tunnel interfaces.Both endpoints will always pick lowest MSS value of the two introduced in TCP headers in SYN and SYN ACK.

What I would do first of all is check the tunnel to see what is maximum data you can send.

For example:

ping sou df-bit size 1300
  1. Ping from both your hub and spoke and should be tunnel IP addresses.
  2. Increase the size in incrementes of 10 to see where it will start failing.

This is how you can check the path MTU between hub and spoke (of course one of possible ways).

Cisco forum

cisco_vpns_and_mtu.1475214917.txt.gz · Last modified: 2016/09/30 15:25 by Dan Mundy