/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Fuzzy Fox wrote:
> Lourdes Jones <[EMAIL PROTECTED]> wrote:
> >
> > As far as I understand it, ethernet device MTU - 8 = MTU of PPPoE. So
> > setting both of these items to match will still produce fragmented
packets
> > which seems to be the likely cause of your stalls.
> >
> > Have you tried setting eth0 1500, ppp0 1492, eth1 1492?
>
> That sets things up on the masq box, but there is yet another ethernet
> interface, that of the masq CLIENT, which would also need to be set to
> 1492. This would keep the client from sending packets that need to be
> fragmented.
I had understood that the client machines were already set at 576.
> > Though to be honest it seems some Websites turn off MTU discovery and
> > ship everything out at 1500 which will always produce fragmented
> > packets on your system.
>
> True enough, but as long as they don't set the "DF" (Don't Fragment) bit
> in the IP header, nothing will break.
That presumes that the linux box is properly handling fragmented packets.
My concern was that the Masq box was not handling fragmented packets
properly. [I seem to remember fragmented packet handling for masqued
packets was broken on some of the ports for a bit.]
> It's the servers that use the DF
> bit to perform Path MTU Discovery, and fail to get the proper ICMP
> messages back, that break down.
I've run into boxes where someone set DF on, MTU 1500 and then blocked all
inbound ICMP traffic. My bank was that way for a while when they first set
up their secured server. :(
Lourdes
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.