Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Oct 2003 13:03:44 -0800
From:      Lars Eggert <larse@ISI.EDU>
To:        Eric Masson <e-masson@kisoft-services.com>
Cc:        Mailing List FreeBSD Network <freebsd-net@FreeBSD.org>
Subject:   Re: ipsec tunnels & packet length issues
Message-ID:  <3FA02B30.90805@isi.edu>
In-Reply-To: <8665iehd1i.fsf@t39bsdems.interne.kisoft-services.com>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Eric Masson wrote:
> 
> If i reduce  lan interface mtu on "Host" to approximately 1450, the
> tunnel works fine, so it seems that "Tunnel Endpoint" can't process
> correctly packets with a size of 1500 bytes.
> 
> If more information regarding this issue is needed, just ask.
> Is this a known issue ?
> Except playing with mtu, is there a fix ?

See the section on PMTU discovery in draft-touch-ipsec-vpn-06. If the 
requirements of your setup allow is, IPIP gif tunnels together with 
IPsec transport mode (as described in the ID) can address this issue.

Lars
-- 
Lars Eggert <larse@isi.edu>           USC Information Sciences Institute

[-- Attachment #2 --]
0	*H
010	+0	*H
	080fErtcvE.0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
040827235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B	li+@]jy.%݊
Z<D&iHΥbb090
vo0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
030801172929Z
040731172929Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
>ן~H(ԢGV׆־25B03ݰת^RIH=%J
kA^R)yH80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU?V0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
5Kkt[@jj:Fg	Xj(8yPo!})5M[	ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!090
vo0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
030801172929Z
040731172929Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
>ן~H(ԢGV׆־25B03ݰת^RIH=%J
kA^R)yH80P~qrU|c~\;ҋ^哪!֍&d@Cd"O"f$FrGe|r<z"%h+Z`3<}̘}9ʮcnb6RX ٫e~XgK7,ìEYU?V0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
5Kkt[@jj:Fg	Xj(8yPo!})5M[	ش]wʼnQd!GyFRiKd!8h\7γSD`a[qiY+Gqn?!100010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0	+0	*H
	1	*H
0	*H
	1
031029210344Z0#	*H
	1})KaǨ<dzvy%0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30
vo0
	*H
н9aM

0[B)Cny#pqդiHQ' lAvMvVÊ6r);G?pMWZPwvklOoIDD|NޟpJ/
:$Q-_B-v,2JC$R*)D~-%H2;pE_	:P#	عP]ر_A83!t;0Rk>g;?k;
home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3FA02B30.90805>