So if PMTU is working for you then you can go to the next level and that is to transfer the ICMP 3-4 to the clients and so no need to do anything about the MTU in Mangle and worry about NAT. This is done in IPSEC Policies and this a script to add the needed line. /ip ipsec policy move *ffffff desti...