Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




firewall-wizards logo Firewall Wizards mailing list archives

R: MTU issue routing traffic via Cisco GRE tunnel to Nokia/Check Point firewall
From: "edp" <edp.lists () acerbis it>
Date: Thu, 18 Dec 2003 09:46:32 +0100

The simple solutions are:
- - use 'ip tcp adjust-mss 1400' on a router seeing traffic in the
clear to > force MSS to 1400 so IP datagram size to 1420 (of course 1400
is just a >guess), this will cover all TCP traffic
- - set 'ip mtu 1500' on the GRE tunnel interface (yes 1500 bytes)


Just for clarity, with a mss option set to 1400, the ip packet size will
be 1440.




_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]