Unix Technical Forum

Re: scrub reassemble tcp and nat causes problems with some sites

This is a discussion on Re: scrub reassemble tcp and nat causes problems with some sites within the lucky.openbsd.misc forums, part of the OpenBSD category; --> On Wed, 19 Jul 2006, Sebastian Benoit wrote: > This sounds like a MTU problem. Either those sites are ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:50 AM
Walter Haidinger
 
Posts: n/a
Default Re: scrub reassemble tcp and nat causes problems with some sites

On Wed, 19 Jul 2006, Sebastian Benoit wrote:

> This sounds like a MTU problem. Either those sites are blocking


Unlikely. I have cable, not a PPTP/PPPoE link. Therefore, no packet
encapsulation. I'm aware of the MTU issue with ADSL.

> ICMP-frag-needed messages or you are.


I think I am. _Only_ reassemble tcp breaks things, but why?

> - set the correct MTU
> - check pf.conf for "scrub max-mss [...]"


No changes necessary, IMHO.

> - google


Have done this, of course. Turned up e.g.:
http://www.benzedrine.cx/pf/msg07352.html
http://monkey.org/openbsd/archive/bu.../msg00059.html

Similar problem but no solution.

> - why do you use no-df?


Because of the NFS issue mentionied in pf.conf(5) and the FAQ.
May not be useful on the external interface, though.
However, the problem persists even without no-df.

Regards,
Walter

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 07:36 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com