PMTUD doesn't work with IPsec
PMTUD doesn't work with IPsec, creating a black hole that causes connectivity problems at times. Best work around is to add a scrub line for IPsec VPNs, e.g. for each internal interface:
scrub in on $LAN from any to <vpns> max-mss 1420
where 1420 is default, and configurable under System > Advanced somewhere along with a checkbox to disable if desired.