Re: Wireguard IP packets fragmentation issue

2022-05-14 Thread Jason McIntyre
On Sat, May 14, 2022 at 09:14:36PM -, Stuart Henderson wrote: > On 2022-05-14, Georg Pfuetzenreuter wrote: > > pppoe(4) already has a section on this, possibly this could be used as a > > start. > > It's not a great start really. Mixes up information about a method to > set the pppoe MTU to

Re: Wireguard IP packets fragmentation issue

2022-05-14 Thread Stuart Henderson
On 2022-05-14, Georg Pfuetzenreuter wrote: > pppoe(4) already has a section on this, possibly this could be used as a > start. It's not a great start really. Mixes up information about a method to set the pppoe MTU to 1500 (RFC4638) and using scrub, doesn't describe the problem (says "causing co

Re: Wireguard IP packets fragmentation issue

2022-05-14 Thread Stuart Henderson
On 2022-05-14, n18fu...@tutanota.com wrote: >> I recommend "max-mss" instead of no-df, you don't really want fragments >> if you can help it. The number to cap at is 40 below the lowest actual >> MTU across the tunnel, so 1380 should do for WireGuard, IPsec varies >> depending on the options used.

Re: calling all PFsync users for experience, gotchas, feedback, tips and tricks

2022-05-14 Thread Tom Smyth
Hello all, Thanks for the feedback it is really helpful to have peoples experiences in the wild to help feed into the training course content. and certainly better than just my humble experience I really appreciate all of your feedback. Thanks again folks, Tom Smyth Tom Smyth On Fri, 13 May 20

using dtb file

2022-05-14 Thread S V
Hello, can anybody give me some pointers on using the dtb file for arm board? I have dtb file from linux, must I recompile it for OpenBSD from dts? Any specific place to put it or just boot image root and load with machine dtb ? How can I check that it is read? Is it even used by OpenBSD? boa

Re: Wireguard IP packets fragmentation issue

2022-05-14 Thread Stuart Henderson
On 2022-05-14, William Ahern wrote: > On Fri, May 13, 2022 at 11:10:41PM +0200, n18fu...@tutanota.com wrote: >> Hi, >> >> I've set up an OpenBSD server on the Cloud, set up a Wireguard tunnel, and >> configured default route through that server. I've noticed that I can't >> access some websites: