Re: IPSec MTU woes

2024-11-27 Thread Pascal Stumpf
On Wed, 27 Nov 2024 17:23:53 +0100, Pascal Stumpf wrote: > On Sat, 23 Nov 2024 15:25:15 +0100, Pascal Stumpf wrote: > > On Sat, 23 Nov 2024 13:42:45 - (UTC), Stuart Henderson wrote: > > > On 2024-11-23, Pascal Stumpf wrote: > > > > Scenario: 7.6-stable running on a gateway, connected to the in

Re: IPSec MTU woes

2024-11-27 Thread Pascal Stumpf
On Sat, 23 Nov 2024 15:25:15 +0100, Pascal Stumpf wrote: > On Sat, 23 Nov 2024 13:42:45 - (UTC), Stuart Henderson wrote: > > On 2024-11-23, Pascal Stumpf wrote: > > > Scenario: 7.6-stable running on a gateway, connected to the internet via > > > pppoe0 over vlan7, several downstream /24 networ

Re: IPSec MTU woes

2024-11-23 Thread Pascal Stumpf
On Sat, 23 Nov 2024 13:42:45 - (UTC), Stuart Henderson wrote: > On 2024-11-23, Pascal Stumpf wrote: > > Scenario: 7.6-stable running on a gateway, connected to the internet via > > pppoe0 over vlan7, several downstream /24 network segments. iked(8) is > > serving several clients, running most

Re: IPSec MTU woes

2024-11-23 Thread Stuart Henderson
On 2024-11-23, Pascal Stumpf wrote: > Scenario: 7.6-stable running on a gateway, connected to the internet via > pppoe0 over vlan7, several downstream /24 network segments. iked(8) is > serving several clients, running mostly Mac OS, with policies like this: > > ikev2 "foo" esp \ > from 192

IPSec MTU woes

2024-11-23 Thread Pascal Stumpf
Scenario: 7.6-stable running on a gateway, connected to the internet via pppoe0 over vlan7, several downstream /24 network segments. iked(8) is serving several clients, running mostly Mac OS, with policies like this: ikev2 "foo" esp \ from 192.168.100.1 to dynamic \ from 192.168.5