From mboxrd@z Thu Jan 1 00:00:00 1970 From: John Hawley Subject: Re: TCPMSS workaround on OUTPUT? Date: 30 Sep 2002 09:38:55 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1033396735.23494.14.camel@magnum> References: <1033056377.562.49.camel@maximus> <3D937473.4000504@bewegungsmelder.de> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="=-OQEkFlGcY3oVSNXLLzvY" Return-path: In-Reply-To: <3D937473.4000504@bewegungsmelder.de> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Thomas Lussnig Cc: Netfilter List --=-OQEkFlGcY3oVSNXLLzvY Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On Thu, 2002-09-26 at 15:56, Thomas Lussnig wrote: first your entry is working, but i think that the filter could=20 "--tcp-flags SYN,RST,ACK SYN" Because "ACK,SYN" as part 2 of the handshake there the MSS should=20 already be known. well, I was just copying ver batim out of the kernel build docs ... And i think that you should tell the direction (-o ppp+ maybe) =20 Local packages should know the correct size since the interface (DSL=20 maybe) have the correct mtu. ok, so is there a kernel bug? I dont seem to have this problem on kernels previous to 2.4.18. That is, that the fw machine itself can't browse these web sites. The two situations I've seen so far are: (1) fw (kernel 2.4.18) --> Cisco router with fractional T1 and (2) fw (kernel 2.4.19) --> Lucent Pipeline on ISDN. =20 Examplke > ip ad li ppp0 19: ppp0: mtu 1492 qdisc cbq qlen 3 link/ppp inet 217.233.244.33 peer 217.5.98.168/32 scope global ppp0 =20 Try this ip ro ch 10.0.1.0/24 dev eth1 advmss 1490 on my networked this make all things working nice WITHOUT the=20 clamp-mss-to-pmtu iptables entry. didn't help =20 Cu Thomas Lu=DFnig =20 =20 --=20 John Hawley BGEA/ITS <=3D> Network Admin 612.335.1334 jhawley@bgea.org --=-OQEkFlGcY3oVSNXLLzvY Content-Type: text/html; charset=utf-8 On Thu, 2002-09-26 at 15:56, Thomas Lussnig wrote:
first your entry is working, but i think that the filter could 
"--tcp-flags SYN,RST,ACK SYN"
Because "ACK,SYN" as part 2 of the handshake there the MSS should 
already be known.
well, I was just copying ver batim out of the kernel build docs ...
And i think that you should tell the direction (-o ppp+ maybe)

Local packages should know the correct size since the interface (DSL 
maybe) have the correct mtu.
ok, so is there a kernel bug?  I dont seem to have this problem on kernels previous to 2.4.18.  That is, that the fw machine itself can't browse these web sites.  The two situations I've seen so far are:  (1) fw (kernel 2.4.18) --> Cisco router with fractional T1 and (2) fw (kernel 2.4.19) --> Lucent Pipeline on ISDN.

Examplke
 > ip ad li ppp0
19: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP> mtu 1492 qdisc cbq qlen 3
    link/ppp
    inet 217.233.244.33 peer 217.5.98.168/32 scope global ppp0

Try this
ip ro ch 10.0.1.0/24 dev eth1 advmss 1490
on my networked this make all things working nice WITHOUT the 
clamp-mss-to-pmtu iptables entry.

didn't help

Cu Thomas Lußnig

-- 
John Hawley
BGEA/ITS <=> Network Admin
612.335.1334
jhawley@bgea.org
--=-OQEkFlGcY3oVSNXLLzvY--