[Openswan dev] [Openswan Users] Fragmentation/reassembly bad
hno at marasystems.com
Tue Jan 11 18:05:51 CET 2005
On Tue, 11 Jan 2005, Marcus Better wrote:
> I and others have had a similar problem with fragmentation. It might be the
> same bug. It has also been reported here:
> The temporary fix is to use Netfilter to force the MSS to something smaller:
> $IPTABLES -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1404
This approach works around PMTU Discovery malfunctions in the network by
forcing TCP to only send small segments.
It is a somewhat ugly thing to do, and only works for TCP traffic (not
UDP), but sometimes workarounds is the best one can do..
More information about the Dev