Paul Wouters <p...@nohats.ca> wrote: > On Aug 1, 2023, at 12:56, Daniel Migault <mglt.i...@gmail.com> wrote: >> >> Hi Ben, Just trying to position our understanding of the position >> between the ICMP PTB and the IKE PTB. If an incoming Encrypted packet >> is larger than the Link MTU
> How can than be? You mean you received an ESP or ESPinUDP that after > decrypting was too large for the link you need to send the decrypted > packet on? That seems really odd. Odd if you think it's all 1500 byte ethernet. And there are no further tunnels. Could come out of an ESP SA and try to go into an ESP-in-UDP SA, and it might not fit. Many people would like to use 9000 byte ethernet across VPN links. Such as the physical people. -- Michael Richardson <mcr+i...@sandelman.ca> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide
signature.asc
Description: PGP signature
_______________________________________________ IPsec mailing list IPsec@ietf.org https://www.ietf.org/mailman/listinfo/ipsec