S
S
scamp2011-01-09 22:57:50
FreeBSD
scamp, 2011-01-09 22:57:50

FreeBSD, change MSS?

There is a basin with several ezernets, the gre-tunnel is terminated on it.
The part of clients comes on ezer, a part on pptp from NAS on the next basin.
There is pf, without nat, in all pass no state rules.
Those who are connected via ezer with MTU 1500 cannot get to some sites (including Habr) that are visible through this gre tunnel. The specificity of these hosts is such that all packets from them contain the DF flag.
Tell me an effective way to tune TCP MSS in passing traffic for FreeBSD, I
included in pf scrub on gre0 fragment reassemble max-mss 1436 , but unfortunately it did not help, perhaps because all the rules below are without keep state.
I tried to use ng_tcpmss, the traffic passes through the node, there is no effect.

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question