[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: isakmpd and icmp dependencies



Todd Boyer wrote:

>My thought is if packets need
>to be fragmented, without the proper icmp response, the peer waits
>indefinitely for instructions on how top handle the request.  Is my thought
>process correct?
>
That's possible, if you've PMTU-discovery enabled.
But the first question is "do they block ESP packets"!

> Any way around this problem?
>
Disable PMTU-discovery or reduce MMTU

> Maybe setting the max MTU to a
>lower value?
>
It's always a good idea.
Cedric