Re: Transparent troubles using GRE / iproute2 / fwmark for linux

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 12 Nov 1999 08:39:11 +0100

David Nillesen wrote:

> However, if you are accessing it via the tunnel from our remote pop it
> fails to work. It will connect to the squid box, the request is getting
> redirected there ( i ran sniffit to make sure) but it justs sits there and
> does nothing. This is for transparent only. You will see "connecting to
> www.altavista.com" ....."transferring data" and then it just sits there.

Sounds like it could be MTU related problems. Path MTU discovery does
not work well together with transparent redirection of TCP traffic.

Workaround:

a) Make sure all redirected paths uses at least the same MTU as the
proxy box for traffic flowing towards the clients.

b) Or disable Path MTU discovery on the proxy box.

--
Henrik Nordstrom
Squid hacker
Received on Fri Nov 12 1999 - 01:01:39 MST

This archive was generated by hypermail pre-2.1.9 : Wed Apr 09 2008 - 11:57:32 MDT