MTU can be adjusted via two ways: 1) Adjusting the MTU of the physical interface where the IPsec tunnel is bound to. This method will not only affect the VPN traffic but all traffic which is traversing the physical interface as well. 2) Changing the encryption algorithms. Stronger encryption algorithms equals to lower MTU …

[ZyWALL/USG] How to configure an SSL VPN rule for full Overview. The SecuExtender client is a tool used to establish an SSL VPN connection between a client PC and a Zyxel security appliance. Once connected the user has access over the security appliance local network or can send all traffic, including internet, through the tunnel (depending on SSL VPN rule setup). Fortigate VPN interface mtu : networking Jul 20, 2008 Route Based VPN - Check Point Software

what if remote VPN end has only 1500 MTU in that case packet will get fragments right? or there is a way to set tunnel MTU – Satish Mar 21 '18 at 19:22 1 TCP header is bigger than 20 bytes when it contains options. – hertitu Mar 25 '18 at 0:15

Example customer gateway device configurations for dynamic add vpn tunnel 1 type numbered local 169.254.44.234 remote 169.254.44.233 peer AWS_VPC_Tunnel_1 set interface vpnt1 state on set interface vpnt1 mtu 1436 Repeat these commands to create the second tunnel, using the information provided under the IPSec Tunnel #2 section of the configuration file. [ZyWALL/USG] How to configure a User Based PSK VPN tunnel VPN Connection (Phase 2): Now that the VPN Gateway (Phase1) rule has been created click on the "VPN Connection" tab to insert the Phase 2 rule for the VPN tunnel.Click the Add button to insert a new rule entry. On the top left of the window click the "Show Advance Settings" button to view all available setup options in the menu.

On the note about adjusting the MTU of the IPSec tunnel: Aruba support says this: Regarding the MTU change option for the site to site VPN, we do not have any specific configuration with which we can change the site to site VPN MTU. My response: I am not satisfied with your response about being able to adjust the MTU on a VPN tunnel.

When an MTU is discovered for a peer, all tunnels to this peer are set to the same MTU. That means that if an Edge has one link with an MTU of 1400 bytes and one link with an MTU of 1500 bytes, all tunnels will have an MTU of 1400 bytes. This ensures that packets can be sent on any tunnel at any time using the same MTU. How To Guide: Set Up & Configure OpenVPN client/server VPN