Hi! > On Wed, 23 Apr 2003, Mathias Sundman wrote: > > If a mashine on LocalNet1 sends full size packets (1500b) > > to a mashine on LocalNet2, it will exceed 1500 bytes > > when it´s encrypted and sent over the internet. These packets > > will then be fragmented. This is fine as long as the fragments > > gets through... > > How about using -j TCPMSS --clamp-mss-to-pmtu > or setting mtu to a lower value to avoid fragmentation ? But if one or more routers in tracepath does not support pmtu? Setting mtu to lower is solution, but this not always good idea. Another solution may be in clear DF flag on forwaders packets. -- /bye ---------------------------------------------------------------------- Dmitry U.Labutcky System administrator of Swift Trace mail to: avl@xxxxxxxxxx Simferopol, Crimea, Ukraine phone: +380-652-516546 Yaltinskaya 20, office 502