> > > have you a; > > iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMMS \ > - --clacmp-mss-to-ptmu Yes! I did it! And it does't work... :-( > > kind of statment in your rules, often require with VPN/s that work with > smaller packet sizes due to increasing headers... That's exactly the problem! The clients should receive an ICMP frag needed packet in order to reduce the packet size, however my proxy/router does not forward the ICMP msg to them! WHY?!?!?! The are no iptables rules that block ICMP! > > > Thanks, > > Ron DuFresne > - -- Thanks to you! -- Leonardo Arena