On Tue, 6 Jul 2004 20:40:34 +0100 Jamie Lokier <jamie@shareable.org> wrote: > Stephen Hemminger wrote: > > Recent TCP changes exposed the problem that there ar lots of really > > broken firewalls that strip or alter TCP options. When the options > > are modified TCP gets busted now. The problem is that when we > > propose window scaling, we expect that the other side receives the > > same initial SYN request that we sent. If there is corrupting > > firewalls that strip it then the window we send is not correctly > > scaled; so the other side thinks there is not enough space to send. > > If a firewall strips the window scaling option in both directions, > then window scaling is disabled (RFC 1323 section 2.2). > > Are you saying there are broken firewalls which strip TCP options in > one direction only? It appears so. - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html