OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Cannot send over VPN link.

From: Anthony Metcalf (anthony.metcalfanferny.ath.cx)
Date: Thu Oct 27 2005 - 08:40:20 CDT


On Thu, 27 Oct 2005 09:29:05 -0400 (EDT)
wietseporcupine.org (Wietse Venema) wrote:

> > I can connect with telnet from the mail server to the other side and
> > send email that way.
>
> Yes, you can, because with telnet the mail is sent one line at a
> time. Each IP datagram is only a few dozen bytes long.
>
> When mail is sent via SMTP, multiple lines are sent as one IP
> datagram of up to the MTU size, usually 1460 bytes.
>
> You have an MTU problem. Either reduce the MTU on the sending host,
> turn off IP PATH MTU discovery on the sending host, or fix that
> router to give proper IP PATH MTU discovery feedback.
>
> Wietse

That sounds like a reasonable explanation, but went right over my head!
Any chance of more info on how I would find out:-
1) what the MTU currently is?
2) What a better value for it would be?
3) if the IP PATH MTU is on or off
4) How I would see if the router is "broke" or how I would fix it? (key
words to search for here will be fine!)

As it no doubt matters to the rest, this box runs Gentoo linux with
postfix 2.1.5.

Thanks a lot for you quick response. Much appreciated.

Anthony

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDYNjJB7soGsFmzMQRAjGRAJ9uWgJmhw08ZGQNsauEqKCsgK/+5ACfW0zo
6O7lpPS84a7u98G1cMpnjIg=
=cA+i
-----END PGP SIGNATURE-----