Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Dmitry Labutcky <avl@strace.net>
To: netfilter@lists.netfilter.org
Subject: Re: Match DF ( Don´t Fragment) bit
Date: Fri, 25 Apr 2003 12:43:40 +0300	[thread overview]
Message-ID: <200304251243.40088.avl@strace.net> (raw)
In-Reply-To: <Pine.LNX.4.51.0304251108380.9600@dns.toxicfilms.tv>

Hi!

> On Wed, 23 Apr 2003, Mathias Sundman wrote:
> > If a mashine on LocalNet1 sends full size packets (1500b)
> > to a mashine on LocalNet2, it will exceed 1500 bytes
> > when it´s encrypted and sent over the internet. These packets
> > will then be fragmented. This is fine as long as the fragments
> > gets through...
>
> How about using -j TCPMSS --clamp-mss-to-pmtu
> or setting mtu to a lower value to avoid fragmentation ?

But if one or more routers in tracepath does not support pmtu?
Setting mtu to lower is solution, but this not always good idea.
Another solution may be in clear DF flag on forwaders packets.


-- 
/bye
----------------------------------------------------------------------
Dmitry U.Labutcky                  System administrator of Swift Trace
mail to: avl@strace.net            Simferopol, Crimea, Ukraine
phone:   +380-652-516546           Yaltinskaya 20, office 502



  reply	other threads:[~2003-04-25  9:43 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-04-23 15:24 Match DF ( Don´t Fragment) bit Mathias Sundman
2003-04-25  9:15 ` Maciej Soltysiak
2003-04-25  9:43   ` Dmitry Labutcky [this message]
2003-04-25 20:00 ` Martijn Lievaart

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200304251243.40088.avl@strace.net \
    --to=avl@strace.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox