Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure I completely understand your situation, but turning down the MTU on an intermediate router is rarely a good fix for PMTU issues. If you have web servers, you may consider turning down the MTU on the Internet facing interfaces. Even if you turned it down to say 1400, you'd only have around 5% more packets ... probably not enough load increase to melt your routers.

In fact, I just ran some test TCP connections against Google, and their web servers respond a TCP MSS of only 1430, suggesting they are assuming a PMTU of 1470. That sounds pretty pragmatic to me and I wouldn't be surprised if other large Internet companies did a similar thing.



The way this expresses itself is some web sites work and some just hang. Looking at the traffic with wireshark you see packets go in but they don't come back. But other web sites work just fine. So you start ratcheting down the MTU size on the outbound router until the non-functioning web site starts returning your calls. Doing ping's with various sized packets can (if the server is responding to pings) also identify the longest packet you can send before someone between you and them decided they want a different fragment size.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: