From owner-freebsd-net@FreeBSD.ORG Tue Oct 25 13:58:40 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6BEF716A41F for ; Tue, 25 Oct 2005 13:58:40 +0000 (GMT) (envelope-from tataz@tataz.chchile.org) Received: from smtp2-g19.free.fr (smtp2-g19.free.fr [212.27.42.28]) by mx1.FreeBSD.org (Postfix) with ESMTP id 05E7D43D5D for ; Tue, 25 Oct 2005 13:58:39 +0000 (GMT) (envelope-from tataz@tataz.chchile.org) Received: from tatooine.tataz.chchile.org (vol75-8-82-233-239-98.fbx.proxad.net [82.233.239.98]) by smtp2-g19.free.fr (Postfix) with ESMTP id 1DCE4521B4; Tue, 25 Oct 2005 15:58:38 +0200 (CEST) Received: by tatooine.tataz.chchile.org (Postfix, from userid 1000) id 90445405A; Tue, 25 Oct 2005 15:58:17 +0200 (CEST) Date: Tue, 25 Oct 2005 15:58:17 +0200 From: Jeremie Le Hen To: VANHULLEBUS Yvan Message-ID: <20051025135817.GN14063@obiwan.tataz.chchile.org> References: <4358082A.4060409@vwsoft.com> <43581E7F.5080305@vwsoft.com> <20051021071039.GA1876@zen.inc> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20051021071039.GA1876@zen.inc> User-Agent: Mutt/1.5.10i Cc: freebsd-net@freebsd.org Subject: Re: IPSec session stalls X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Oct 2005 13:58:40 -0000 > Not sure: what you described in your first mail also looks like a > "basic" fragmentation problem, which can be easily solved by > decreasing MTU on traffic endpoints (you can also play with TCPMSS on > one gate, but this will only solve TCP problems...). > > The pf interaction may only be a side effect of a fragmentation > problem. Hi also have problems with my IPSec tunnel. IIRC from tests that I made, this is a Path MTU Discovery problem. I described a similar problem here, but never succeeded to resolve it, unfortunately. Note that I didn't use pf. It is described here : http://lists.freebsd.org/pipermail/freebsd-net/2005-July/007899.html Regards, -- Jeremie Le Hen < jeremie at le-hen dot org >< ttz at chchile dot org >