Thank you for sharing this! Since we have started putting things in a wiki,
I've copied your email to


> iptables -t mangle -A OUTPUT -p udp --sport 4500 -d x.x.0.0/16 -m length --length 29 -j TTL --ttl-set 6

I'm curious why you are matching on length 29?

Is that a determined magic length of these keep-alive packets?


