DF is required for vxlan. Pmtud doesn’t necessarily work with a L2
tunnel either. You may be able to configure the firewall to ignore DF
bit on ipsec encap/decap, but performance will likely suffer. You really
need vxlan-routing instead of bridging f...