You have packet loss on an IPsec VPN using the default maximum transmission unit (MTU) where
the packets have the DF-bit (do not fragment) set.
Which configuration solves this problem?
A.
Set an increased MTU value on the physical interface.
B.
Set a reduced MSS value for VPN traffic under the [edit security flow tcp-mss] hierarchy.
C.
Set a reduced MTU value for VPN traffic under the [edit security flow] hierarchy.
D.
Set an increased MSS value on the st0 interface.
http://www.juniper.net/techpubs/en_US/junos12.1×46/topics/example/session-tcp-maximum-segment-size-for-srx-series-setting-cli.html