Firewall Wizards mailing list archives

R: MTU issue routing traffic via Cisco GRE tunnel to Nokia/Check Point firewall


From: "edp" <edp.lists () acerbis it>
Date: Thu, 18 Dec 2003 09:46:32 +0100

The simple solutions are:
- - use 'ip tcp adjust-mss 1400' on a router seeing traffic in the
clear to > force MSS to 1400 so IP datagram size to 1420 (of course 1400
is just a >guess), this will cover all TCP traffic
- - set 'ip mtu 1500' on the GRE tunnel interface (yes 1500 bytes)


Just for clarity, with a mss option set to 1400, the ip packet size will
be 1440.




_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: