R: Re: mtu issue with ipsec tunnel and netfilter snat

From: pupilla@libero.it <hidden>
Date: 2013-01-09 09:55:45

jengelh@inai.de wrote:
On Wednesday 2013-01-09 10:01, pupilla@libero.it wrote:
quoted
As you can see there are incoming 1500 bytes packets (these are the
decrypted ipsec packets) with DF bit set. These packets are never
delivered to the final client 10.81.128.176 (the destination address
is 172.16.128.1 which is the ip used for SNATing the original ip
10.81.128.176).

IMHO this is a mtu issue: 1500 bytes packets cannot be routed inside
the ipsec tunnel.

But why linux_gw_snat is not sending icmp need to frag packets to
10.148.12.23?
Perhaps because ICMP was blocked erroneously?
No, I have opened the firewall
rules with something like:

iptables -I OUTPUT --proto icmp -j ACCEPT
iptables -I INPUT --proto icmp -j ACCEPT
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help