2 comments on “It is the network

  1. Oh my. Another broken PMTUD. As a good network doctor you will fix the root cause, not only the symptoms. Here it is ICMP “packet too big” messages not reaching the clients (or not beeing genereated) and possibly MTU settings on tunnel interfaces. If at all possible one SHOULD NOT mangle any headers.

    • Indeed, I was never comfortable with the solution, but it was the first time I had dealt with IPSec/GRE and it worked after I cleared the DF bit. I never got another complaint. Please forgive me, I was young and I needed the money 🙂

