|
From: Nikita K. <kos...@gm...> - 2010-08-29 09:35:50
|
On Sat, 28 Aug 2010 23:27:56 +0200 Jan Just Keijser wrote: Thanks for reply, Jan. > Hi Nikita, > > interesting question ... there are a couple of things to try: > - what happens if you specify > tun-mtu 1400 > in the server config file? does the DF work then No, the tun interface is up with tun 1400 (client 1500), but trying to ping with packet size more than 1373, I got: tun packet too large on write (tried=1401,max=1400) Packet size > 1376: Authenticate/Decrypt packet error: packet HMAC authentication failed No icmp replies in both cases. > - what happens if you switch to 'tap' ? a 'tun' device is a > point-to-point device and is not the exact equivalent of an ethernet > device. A 'tap' device comes much closer > Tap has the same behavior: Manually set mtu 1300 after interface is up and ping with packet size > mtu - got fragmented reply. Fragmentation happens on tap device, eth0 send and receive full size packets. DF is set in requests. Any ideas ? |