LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-26-2014, 11:29 PM   #1
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Rep: Reputation: Disabled
strongswan - set MTU size?


curious on how to restrict strongswan MTU size without reducing the MTU on the physical interface on which it's running. I'm finding lots of ways to do it via iptables MSS clamping, but that appears to only work for TCP; strongswan (5.1.3) appears to be using encapsulated UDP, as far as my packet captures can tell.
 
Old 07-27-2014, 06:40 AM   #2
Ser Olmy
Senior Member
 
Registered: Jan 2012
Distribution: Slackware
Posts: 3,348

Rep: Reputation: Disabled
Since IPsec doesn't use tunnel interfaces, the payload size is limited by the MTU of the outgoing interface (and the path MTU, obviously). Unless StrongSwan has a configuration parameter that can limit the payload size (and I don't think such a parameter exists), you're stuck with the interface MTU.

BTW, StrongSwan doesn't "use encapsulated UDP", it uses IPsec/ESP, which in turn may use IPsec NAT Traversal encapsulation (UDP port 4500) if NAT is detected or if you force NAT-T with the relevant parameter.
 
Old 07-27-2014, 10:48 AM   #3
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Original Poster
Rep: Reputation: Disabled
OK, that's what i thought. Thanks for the info.

As an aside, have you ever used Strongswan? If so, what do you think of it? Has it worked well for you?
 
Old 07-27-2014, 11:10 AM   #4
Ser Olmy
Senior Member
 
Registered: Jan 2012
Distribution: Slackware
Posts: 3,348

Rep: Reputation: Disabled
Quote:
Originally Posted by psycroptic View Post
As an aside, have you ever used Strongswan? If so, what do you think of it? Has it worked well for you?
I've only just started using it, but so far it seems to work very well. It has an impressive list of features.

I can't say I'm perfectly happy with the configuration syntax (seriously, "left" and "right"? How about "local" and "remote"?), but all in all it wasn't too difficult to set up connections that would talk to other IPsec equipment.
 
Old 07-27-2014, 11:23 AM   #5
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Original Poster
Rep: Reputation: Disabled
word. Coming from OpenVPN, I am also finding its syntax more squirrely.

Have you tried using it with Android, specifically with the Strongswan app? im noticing lots of random disconnects there, sometimes requiring a phone reboot to be able to reconnect again
 
Old 07-27-2014, 05:09 PM   #6
Ser Olmy
Senior Member
 
Registered: Jan 2012
Distribution: Slackware
Posts: 3,348

Rep: Reputation: Disabled
I haven't used the Android app, but I would suspect the cause of any instabilities to be on the Android side. strongSwan on x86 Linux seems rock solid.
 
Old 07-27-2014, 05:21 PM   #7
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Ser Olmy View Post
strongSwan on x86 Linux seems rock solid.
yeah, same for me going from Linux to Win7.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I am Not able to set MTU size of interface(say eth0/eth1) using Netlink Sockets Sekhar417 Linux - Networking 0 10-05-2012 12:43 AM
loopback interface MTU size free2rhyme2k Linux - Networking 6 02-14-2012 07:57 PM
MTU size 1400 invader44 Slackware 6 01-10-2010 07:50 AM
MTU size, slow webpages jorisb Linux - Software 2 03-12-2004 04:04 PM
MTU size B_Krishnakumar Linux - Networking 21 08-02-2003 11:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration