[Openswan Users] OpenSWAN NetKey MTU Problem?

Harald Scharf h.scharf at nestec.at
Tue Feb 27 15:28:57 EST 2007


I do not know, if icmp gets lost. I will check this.

But..
tcpdump on the TCP connections shows, that the DF Flag is set...

-----Ursprüngliche Nachricht-----
Von: users-bounces at openswan.org [mailto:users-bounces at openswan.org] Im Auftrag von Benny Amorsen
Gesendet: Dienstag, 27. Februar 2007 21:16
An: users at lists.openswan.org
Betreff: Re: [Openswan Users] OpenSWAN NetKey MTU Problem?

>>>>> "HS" == Harald Scharf <h.scharf at nestec.at> writes:

HS> Now, if I want to access a https server over the tunnel,

HS> I get the certificate and then, the connection breaks (timeout).

 

HS> tcpdump on icmp says : fragmentation needed.

Does that icmp message get lost somewhere along the way? That would be my best guess.


/Benny


_______________________________________________
Users at openswan.org
http://lists.openswan.org/mailman/listinfo/users
Building and Integrating Virtual Private Networks with Openswan: 
http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155




More information about the Users mailing list