Rick At 21:14 10.11.2004 -0500, you wrote: >No, didn't set CLAMPMSS. The chief symptom so far has been a bad route. >I think it was an error like >Ioctlsroute or some such code. > >What is the MSS that you would recommend for Ipsec? The SA is getting >established OK so far (so UDP is not the problem). >Rick.
I would just set CLAMPMSS to yes in shorewall.conf. It adapts to the actual MTU size less 40 I believe. Erich THINK Püntenstrasse 39 8143 Stallikon mailto:[EMAIL PROTECTED] PGP Fingerprint: BC9A 25BC 3954 3BC8 C024 8D8A B7D4 FF9D 05B8 0A16 ------------------------------------------------------- This SF.Net email is sponsored by: Sybase ASE Linux Express Edition - download now for FREE LinuxWorld Reader's Choice Award Winner for best database on Linux. http://ads.osdn.com/?ad_idU88&alloc_id065&op=click ------------------------------------------------------------------------ leaf-user mailing list: [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/leaf-user SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html