Traffic is not passing through Gateway, as expected, due to MTU and/or TCP MSS issues.
Latency in traffic running via Site-to-Site VPN.
"IPSEC_mtu_icmp" kernel table is getting full by the relevant connection.
IPSEC_mtu_icmp
Web traffic is dropped when using a PPPoE link, cannot go to any website in a Web browser.
Kernel debug ('fw ctl debug -m fw + drop') shows:fw_log_drop: Packet proto= ... dropped by fwchain_frag Reason: wait for more fragments; ..dropped by fwlinux_nfipout Reason: packet with IP_DF larger than MTU;
fw ctl debug -m fw + drop
fw_log_drop: Packet proto= ... dropped by fwchain_frag Reason: wait for more fragments; ..dropped by fwlinux_nfipout Reason: packet with IP_DF larger than MTU;