Re: Change MTU for forwarded packets

2006-08-18 Thread Martin Schuster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 George Borisov wrote: > Hello, > > Is there a way of forcing an MTU size for forwarded traffic on > the firewall? > I have tried playing with TCPMSS in iptables, but I haven't > managed to get it to work. > This should work automatically afaik. Is yo

Re: Change MTU for forwarded packets

2006-08-18 Thread George Borisov
Martin Schuster wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > George Borisov wrote: >> Hello, >> >> Is there a way of forcing an MTU size for forwarded traffic on >> the firewall? >> I have tried playing with TCPMSS in iptables, but I haven't >> managed to get it to work. >> > This

Change MTU for forwarded packets

2006-08-18 Thread George Borisov
Hello, We have an IPSec VPN link between the UK and South Africa. Unfortunately one of the routers upstream from our South Africa firewall mangles large packets (e.g. only 2/3 chunks of a 4000 byte ping will be received.) This was causing problems for LAN-to-LAN communication. Things like SSH wou