[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: isakmpd and icmp dependencies
Todd Boyer wrote:
>My thought is if packets need
>to be fragmented, without the proper icmp response, the peer waits
>indefinitely for instructions on how top handle the request. Is my thought
>process correct?
>
That's possible, if you've PMTU-discovery enabled.
But the first question is "do they block ESP packets"!
> Any way around this problem?
>
Disable PMTU-discovery or reduce MMTU
> Maybe setting the max MTU to a
>lower value?
>
It's always a good idea.
Cedric