[Openswan Users] MTU problem

David L. Cathey davidc at montagar.com
Thu May 22 11:23:09 EDT 2008


On Wed, 2008-05-14 at 14:44 +0200, Federico Viel wrote:
> Hello,
> I got a problem with my lan to lan openswan vpn:
> Openswan IPsec U2.2.0/K2.6.16.18...
> 
> Local site 10.X.Y.0/24<--------> Openswan <-------> Remote site 10.Z.Y.0/24
> 
> The ipsec tunnel works well but I can’t ping with a 2048 byte size packet
> the remote site: this should be fundamental to windows gpo policy to work
> well….
> At the moment I can ping remote site with a maximum packet size of 1418.
> Is there any solution?

Sounds like you're having similar issues as me.  The only solution I've
found is to disable Path MTU Discovery.

In Linux, you just set net.ipv4.ip_no_pmtu_disc=1 in /etc/sysctl.conf.
In Windows, there's a registry setting for it, but I don't know what it
is.

-- 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
David L. Cathey                      |Inet: davidc at montagar.com
Montagar Software, Inc.              |Fone: (972)-423-5224
P. O. Box 260772, Plano, TX 75026    |http://www.montagar.com



More information about the Users mailing list