ISA only fragments packets in the private to public direction. The following two types of fragmentation are used.
Fragment before GRE encapsulation is controlled by the ip-mtu in the ip-tunnel context.
Fragment after IPsec processing is controlled by the configured encapsulated-ip-mtu in the ip-tunnel context.
ISA only reassembles received ESP packets on the public side before IPsec decryption. The reassembly behavior is controlled by the reassembly command under the tunnel group.