netdev
[Top] [All Lists]

Re: [net-2.6.13 0/3] [IPSEC] Allow PMTU discovery to be turned off

To: herbert@xxxxxxxxxxxxxxxxxxx
Subject: Re: [net-2.6.13 0/3] [IPSEC] Allow PMTU discovery to be turned off
From: "David S. Miller" <davem@xxxxxxxxxxxxx>
Date: Mon, 20 Jun 2005 13:24:01 -0700 (PDT)
Cc: jmorris@xxxxxxxxxx, kaber@xxxxxxxxx, yoshfuji@xxxxxxxxxxxxxx, netdev@xxxxxxxxxxx
In-reply-to: <20050613073353.GA21454@gondor.apana.org.au>
References: <20050613073353.GA21454@gondor.apana.org.au>
Sender: netdev-bounce@xxxxxxxxxxx
From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Mon, 13 Jun 2005 17:33:53 +1000

> One of the problems that's been plaguing our IPsec stack is ICMP
> blackholes.  ICMP blackholes are particularly bad for tunnels because
> the most common remediy -- MSS clamping has no effect when applied
> outside the tunnel.  It is often impractical to apply it inside
> the tunnel since the point where the clamping is applied may be some
> way away from either IPsec endpoint.
> 
> The best solution so far has been to disable PMTU discovery when a
> blackhole is detected.  We already support that for IPIP/GRE tunnels.
> The following patchset adds support for a similar strategy to IPsec
> tunnels.
> 
> It is by no means ideal but it's something that you need to survive
> on today's Internet.

All 3 patches applied, thanks Herbert.

One thing needs clarification in your description.  When I first
read "blackhole is detected" I was under the wrong impression as
to _who_ does the detection.  Your patches allow the administrator
to do this, whereas I thought you were going to add some code which
dynamically figured out the presence of ICMP black holes and would
thus set the bit.

<Prev in Thread] Current Thread [Next in Thread>
  • Re: [net-2.6.13 0/3] [IPSEC] Allow PMTU discovery to be turned off, David S. Miller <=