Tuesday 10 March 2020

Cisco anyconnect - MTU-D packet 1200 bytes greater than effective mtu 986

MTU issues with anyconnect – traffic coming back in from outside as being dropped as it was too big

An error message like this was appearing in ASDM logs
MTU-D packet 1200 bytes greater than effective mtu 986


- conf t
- group-policy SSL--CLIENTS attributes
- webvpn
- anyconnect ssl df-bit-ignore enable

wr
disconnect/reconnect anyconnect and retest

This will ignore the defragmentation of the bits and it will allow the packets to pass through no matter of the MTU size.