On Mon, 2003-09-22 at 10:49, Nigel Metheringham wrote: > On Fri, 2003-09-19 at 17:19, Cedric Blancher wrote: > > Just a 0.02e quick thought... > > You're facing a situation a bit like routing LANs through a PPPoE link. > > Solution is to clamp TCPMSS down to correct value when routing them. > > Interesting idea. I'm not sure these packets go through the FORWARD > table - the rules I have in would not allow them to. However it gives > me something to try playing with - variations using another table > probably. OK, I was talking utter rubbish... The connection does indeed go through the FORWARD table and there is indeed a set of rules to allow it to do so, written by myself, so my mind has finally gone :-/ Putting a mangle table rule in to clamp MSS does appear to have fixed the problem - just need to redo the whole test from scratch to ensure I haven't something else in the chain thats affecting it. Nigel. -- [ Nigel Metheringham Nigel.Metheringham@xxxxxxxxxxxxxxxxxx ] [ - Comments in this message are my own and not ITO opinion/policy - ]