Subject: 2.0.2 + IPNAT + MSS clamping?
To: None <port-i386@netbsd.org>
From: Steve Paul <xeglon@earthlink.net>
List: port-i386
Date: 09/19/2005 17:48:25
Greetings list,
I've had a number of issues from a 1.6 -> 2.0.2 upgrade, most revolve
around mss clamping issues.
Dual-homed server: PPPoE0, 1492 MTU, tried mss clamping/ipnat of 1440,
1460 and 1420.
My only issue is with a naughty server behind a router with full ICMP
filtering using MTU discovery. It seems the clamping may not be taking
effect as I can connect with a Debian box with any clamping size between
1450 to 1420. NetBSD 2.0.2 with custom kernel will not. All normal
nat/ipf rules work fine. It's a single server with this problem with
the ICMP filtering (no traceroutes or pings work).
My question is, are there any known issues with 2.0.2 release, PPPoE,
IPNAT and mss clamping? I found some old maillist threads from 1.6 and
2.0A, but nothing descript about fixes nor any mention of 2.0.2+.
I'm going to perform more tcpdump research into the issue, but from all
angles, it appears mssclamping isn't working properly in 2.0.2 + ipnat.
Any tips, direction or insights greatly appreciated.
Cheers,
Steve