Project

General

Profile

Actions

Feature #15827

open

enable by default MSS for all IPsec VTI

Added by Mike Moore 16 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

According to netgate documenation, if using IPsec VTIs, you have to set the MSS value for each interface

https://docs.netgate.com/pfsense/en/latest/config/advanced-firewall-nat.html#mss-clamping

My request is to have an option to set MSS for all interfaces that are VTI. Right now i have over 30 VTI tunnels and planning on doing more in the future. I had to spot check a few VTI interfaces to ensure the correct MSS value was set and some did not. It would be helpful to have the ability within the IPsec advanced configuration to set an MSS or MTU for all IPsec VTI interfaces.

No data to display

Actions

Also available in: Atom PDF