[96394] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: barak-online.net icmp performance vs. traceroute/tcptraceroute, ssh, ipsec

daemon@ATHENA.MIT.EDU (Lincoln Dale)
Mon May 7 18:44:37 2007

From: "Lincoln Dale" <ltd@interlink.com.au>
To: "'Joe Maimon'" <jmaimon@ttec.com>,
	"'Jo Rhett'" <jrhett@svcolo.com>
Cc: "'Steven M. Bellovin'" <smb@cs.columbia.edu>,
	"'nanog'" <nanog@merit.edu>
Date: Tue, 8 May 2007 08:41:45 +1000
In-Reply-To: <463F6A5D.7050408@ttec.com>
Errors-To: owner-nanog@merit.edu


> Lower than 1500 mtu always requires some kind of hack in real life.
> 
> That would be the adjust-mss which is the hack-of-choice

note that using 'adjust-mss' only adjusts the MSS for TCP.
it won't do much good for already-encapsulated IPSec traffic with protocol 47
or tunneled over UDP...



cheers,

lincoln.


home help back first fref pref prev next nref lref last post