Shawn Willden <(E-Mail Removed)> wrote:
>
>More to the point, does anyone have any suggestions as to what I can do,
>other than manually lowering my MTUs to match the IPSEC MTU?
You already know what the remedy is, why don't you want to
swallow the pill and cure the disease. It isn't as if there is
some horrible problem with lowering the interface MTU.
In fact, if you want to be really pedantic, lower the MTU to
576. It probably will never bite you, but the specs say that
the TCP buffers do not have to handle more than a 576 byte
payload, hence it is possible that any Internet router could
just up and trash any packet sent with an original MTU larger
than 576. (I haven't heard of anyone implementing a router with
buffers that small, but it would not be outside the specs if
someone did.)
Basically, while the default ethernet frame makes a 1500 byte
MTU reasonable for ethernet traffic, it is also true that if any
IP packets are tunneled through that ethernet, the MTU should be
adjusted downward as is appropriate. PPPoE and apparently your
VPN implementation are two examples.
--
Floyd L. Davidson <http://web.newsguy.com/floyd_davidson>
Ukpeagvik (Barrow, Alaska)
(E-Mail Removed)