All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Frank Wunderlich <frank-w@public-files.de>
Cc: netfilter@vger.kernel.org
Subject: Re: Re: Re: Flowtable with ppp/bridge
Date: Mon, 3 May 2021 23:32:13 +0200	[thread overview]
Message-ID: <20210503213213.GA17087@salvia> (raw)
In-Reply-To: <trinity-140ff956-faa3-4db5-a7b5-b89f01c7b715-1620068208738@3c-app-gmx-bap65>

On Mon, May 03, 2021 at 08:56:48PM +0200, Frank Wunderlich wrote:
> Hi Pablo
> 
> > Gesendet: Montag, 03. Mai 2021 um 00:11 Uhr
> > Von: "Pablo Neira Ayuso" <pablo@netfilter.org>
> 
> > You have to add a rule to clamp TCP mss to path MTU.
> >
> > ... tcp flags syn tcp option maxseg size set rt mtu
> 
> Thanks i try this like described here (just for reference):
> 
> https://wiki.nftables.org/wiki-nftables/index.php/Mangling_packet_headers

I have updated the wiki: you have to mangle the TCP MSS options of the
original syn and the reply syn+ack packets.

> my MTU broadcast via dnsmasq does not work for all client-devices
> 
> but imho this should affect 5.12 and 5.10 without flowtable too
> (because limit is the ppp-tunnel in default Gateway), right?? so it
> looks like flowtable in 5.10 breaks the Path Discovery or prevents
> fragmentation which should normally happen if packets are too big.

Did you try with the rule that mangles both the original syn and the
reply syn+ack packets? Do not restrict mangling to oifname pppoe0.

  reply	other threads:[~2021-05-03 21:32 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-04-26 15:30 Flowtable with ppp/bridge Frank Wunderlich
2021-04-26 17:29 ` Pablo Neira Ayuso
2021-04-26 17:51   ` Frank Wunderlich
2021-04-26 17:57     ` Pablo Neira Ayuso
2021-04-26 18:08       ` Frank Wunderlich
2021-04-27 23:49         ` Pablo Neira Ayuso
2021-04-28  8:07           ` Frank Wunderlich
2021-04-28 17:26             ` Frank Wunderlich
2021-04-29 13:59               ` Aw: " Frank Wunderlich
2021-05-02 13:51                 ` Frank Wunderlich
2021-05-02 22:11                   ` Pablo Neira Ayuso
2021-05-03 18:56                     ` Aw: " Frank Wunderlich
2021-05-03 21:32                       ` Pablo Neira Ayuso [this message]
2021-05-04 10:54                         ` Aw: " Frank Wunderlich
2021-05-04 11:42                           ` Pablo Neira Ayuso
2021-05-05  8:55                             ` Aw: " Frank Wunderlich
2021-05-05 22:55                               ` Pablo Neira Ayuso
2021-05-06  9:53                                 ` Aw: " Frank Wunderlich
2021-05-06 15:51                                   ` Pablo Neira Ayuso
2021-05-10  6:50                                     ` Aw: " Frank Wunderlich
2021-05-10  8:24                                       ` Pablo Neira Ayuso
2021-05-10  9:00                                         ` Aw: " Frank Wunderlich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210503213213.GA17087@salvia \
    --to=pablo@netfilter.org \
    --cc=frank-w@public-files.de \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.