[33452] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IPIP-tunnel with 1500 MTU

daemon@ATHENA.MIT.EDU (Mikael Abrahamsson)
Thu Jan 11 14:43:56 2001

Date: Thu, 11 Jan 2001 20:35:13 +0100 (CET)
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: <nanog@merit.edu>
In-Reply-To: <200101111856.f0BIuCNo13976@black-ice.cc.vt.edu>
Message-ID: <Pine.LNX.4.30.0101112029320.20762-100000@uplift.swm.pp.se>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu


On Thu, 11 Jan 2001 Valdis.Kletnieks@vt.edu wrote:

> Why is it "not acceptable"?  Can you configure a Path MTU of 1450 to avoid
> fragmenting, or run Path MTU Discovery?

<customer location 2>
   |
our router2
   | tunnel
our net
   | tunnel
our router1
   |
<customer location 1>
   |
customers NATbox
   |
customers internetconnection
   |
another machine

The "NEED TO FRAG"-ICMPs generated by our router1 when "another machine"
sends packets with 1500 MTU size and DF flag set will be about RFC1918
adresses when "another machine" think's it's talking to the address of the
NATbox. Breaks everything.

Anyhow, P-MTUd is broken in too many places in the internet anyway.

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se



home help back first fref pref prev next nref lref last post