Re: ppp mru/mtu and ip masquerading

Fuzzy Fox (fox@dallas.net)
Sat, 27 Feb 1999 23:53:42 -0600


Dan Srebnick <dan@islenet.com> wrote:
>
> My ppp mru/mtu was set to 512 for performance reasons. I wondered if this
> might be the problem, and allowed pppd to use 1524 which is what my ISP
> wants to negotiate. The browser on the private network address was now
> able to contact the site.
>
> Might this be a kernel or ipchains problem?

This has been a problem since the 2.0 days, with anyone using IP Masq.
There seems to be an interaction problem when the masq box has a smaller
MTU than the firewalled system, and Path MTU Discovery breaks down. At
some point, the ICMP messages necessary to support it are not being
passed along correctly. Unfortunately, no one seems to have a clear
handle no the nature of the problem. Setting the PPP MTU to be the same
as the ethernet MTU (1500) cures the problem in all cases, but many
people dislike the performance ramifications this has.

-- 
   fox@dallas.net (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/