Date: Wed, 29 Oct 2003 13:03:44 -0800 From: Lars Eggert <larse@ISI.EDU> To: Eric Masson <e-masson@kisoft-services.com> Cc: Mailing List FreeBSD Network <freebsd-net@FreeBSD.org> Subject: Re: ipsec tunnels & packet length issues Message-ID: <3FA02B30.90805@isi.edu> In-Reply-To: <8665iehd1i.fsf@t39bsdems.interne.kisoft-services.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --]
Eric Masson wrote:
>
> If i reduce lan interface mtu on "Host" to approximately 1450, the
> tunnel works fine, so it seems that "Tunnel Endpoint" can't process
> correctly packets with a size of 1500 bytes.
>
> If more information regarding this issue is needed, just ask.
> Is this a known issue ?
> Except playing with mtu, is there a fix ?
See the section on PMTU discovery in draft-touch-ipsec-vpn-06. If the
requirements of your setup allow is, IPIP gif tunnels together with
IPsec transport mode (as described in the ID) can address this issue.
Lars
--
Lars Eggert <larse@isi.edu> USC Information Sciences Institute
[-- Attachment #2 --]
0 *H
010 + 0 *H
080fErtcvE.0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
000830000000Z
040827235959Z010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
*H
0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0
*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B li+@]jy.%݊
Z<D&iHΥbb090
vo0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
030801172929Z
040731172929Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
>ן~H(ԢGV׆־25B03ݰת^RIH =%J
kA^R)y H80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU? V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
5Kkt[@jj:Fg Xj(8yPo!})5M[ ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!090
vo0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
030801172929Z
040731172929Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
>ן~H(ԢGV׆־25B03ݰת^RIH =%J
kA^R)y H80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU? V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
5Kkt[@jj:Fg Xj(8yPo!})5M[ ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!100010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0 + 0 *H
1 *H
0 *H
1
031029210344Z0# *H
1})KaǨ<dzvy%0R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0 +710010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0*H
1010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0
*H
н9aM
0[B)Cny#pqդiHQ' lAvMvVÊ6r);G?pMWZPwvklOoIDD|NޟpJ/
:$Q-_B-v,2JC$R*)D~-%H2;pE_ :P# عP]ر_A83!t;0Rk>g;?k;
home |
help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3FA02B30.90805>
