When you say "netbsd router" it makes me wonder if you're trying to control TCP MSS for an entire network behind that router. Are you? Or are you just trying to affect TCP connections that originate or terminate at that router (e.g. BGP, ssh, etc)? curious, Erik <fair@netbsd.org>