5be809bd   
   From: Casper.Dik@Sun.COM   
      
   David Schwartz writes:   
      
   >I can't figure out what you're talking about. What does "enable PMTU   
   >on our end-points" mean? You mean enable PMTU detection? If the   
   >endpoints do PMTU detection, it doesn't matter what the middle does.   
   >The endpoints will figure out the largest packet that arrives   
   >unfragmented.   
      
   No, it requires that packets which are two big and which have DF set:   
    will be dropped   
    an ICMP message will be send.   
    and the ICMP packet will make it to the sender   
      
   In order for the link to support PMTU, all parts in the link must   
   follow the RFCs, including the endpoint and firewalls which may   
   drop all ICMP messages.   
      
   The endpoints don't magically determine the "largest packet that   
   arrived".   
      
   >> How do we reconcile intermediate systems not obeying PMTU, for   
   >> example, a site-to-site VPN across the Internet which clearly needs   
   >> it's MTU lowered?   
      
   >What does "intermediate systems not obeying PMTU" mean? What does it   
   >mean to "obey" a PMTU?   
      
   See above.   
      
   Casper   
   --   
   Expressed in this posting are my opinions. They are in no way related   
   to opinions held by my employer, Sun Microsystems.   
   Statements on Sun products included here are not gospel and may   
   be fiction rather than truth.   
      
   --- SoupGate-Win32 v1.05   
    * Origin: you cannot sedate... all the things you hate (1:229/2)   
|