Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 23 Mar 2020 16:26:47 +0700
From:      Victor Sudakov <vas@sibptus.ru>
To:        "Patrick M. Hausen" <hausen@punkt.de>
Cc:        freebsd-net@freebsd.org
Subject:   Re: IP MTU on gif and gre interfaces (with and without IPSec encryption)
Message-ID:  <20200323092647.GA57111@admin.sibptus.ru>
In-Reply-To: <20200323092104.GA56721@admin.sibptus.ru>
References:  <20200323050012.GA50490@admin.sibptus.ru> <7D560C6A-EB51-414A-A3A1-18587D40C218@punkt.de> <20200323092104.GA56721@admin.sibptus.ru>

next in thread | previous in thread | raw e-mail | index | archive | help

--6TrnltStXW4iwmi0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Victor Sudakov wrote:
> Patrick M. Hausen wrote:
> >=20
> > > Am 23.03.2020 um 06:00 schrieb Victor Sudakov <vas@sibptus.ru>:
> > > I've noticed that a newly created gre0 interface has the expected "mt=
u 1476"
> > > value, but a newly created gif0 interface has "mtu 1280", why would t=
he
> > > default be so low?
> >=20
> > gif is frequently used as the innermost encapsulation like in gif tunnel
> > across host mode IPsec. Then there might be PPPoE, too. Possibly a
> > VLAN tag ...
>=20
> Please correct me if I'm wrong:
>=20
> - ESP overhead - 40 bytes
> - UDP encapsulation of ESP (udp/4500): 8 bytes
> - PPPoE overhead - 8 bytes (?)
> - A VLAN tag just increases the max frame size, it does not reduce the IP=
 MTU.
>=20
> So we could keep the safe default for gif(4) at 1500-40-8-8=3D1444 bytes.
> OK, at 1400 as for if_ipsec. But not at 1280!

I should probably have counted the 20 bytes of the additional IP header
which results in 1500-40-8-8-20=3D1424.

So 1400 is really safe.

--=20
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
2:5005/49@fidonet http://vas.tomsk.ru/

--6TrnltStXW4iwmi0
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEcBAEBAgAGBQJeeIDXAAoJEA2k8lmbXsY087YH+wVNzMozSWG8rUHqoqJLVAHw
aHNKQh+mawIyVO2In+54ed3tQP06UxPYWcbtaH+zoBggdidQBw5MQKkynntSstKT
4LaYZoQO2dP6bO85l44zuR2iT69E1OXauW8jIx6B+avVB/4niedvEZfyCloHcaFg
Mvvw5Gxss3OhMGX5/xggs/XPO0LWke5k8txVTrLywJ0ESv1K44TMTleSv2sXDp1X
Jmwnu6/0xQVRtbSUeSPIFH3dCfHMeev+ft97iOmh4kamrCAmxa3VvavNhCmNc9FT
5N0QfdZNdKa6jS9pJyuu/rHkSBc30b/sPlZnrOsm1wytlcVQdvXggE1K/dgglKI=
=Wpa6
-----END PGP SIGNATURE-----

--6TrnltStXW4iwmi0--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20200323092647.GA57111>