Re: Path MTU Discovery

"Angelos D. Keromytis" <angelos@aurora.cis.upenn.edu> Tue, 11 February 1997 12:44 UTC

Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id HAA16786 for ipsec-outgoing; Tue, 11 Feb 1997 07:44:54 -0500 (EST)
Date: Tue, 11 Feb 1997 07:44:54 -0500
Message-Id: <9702110403.AA85679@aurora.cis.upenn.edu>
To: Ran Atkinson <rja@inet.org>
Cc: Ben Rogers <ben@ascend.com>, Dan McDonald <Dan.McDonald@Eng.sun.com>, ipsec@tis.com
Subject: Re: Path MTU Discovery
From: "Angelos D. Keromytis" <angelos@aurora.cis.upenn.edu>
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

-----BEGIN PGP SIGNED MESSAGE-----


In message <Chameleon.855633160.rja@c8-a.snvl1.sfba.home.com>, Ran Atkinson wri
tes:
>
>  In effect, ESP tunnel mode uses the outer IP as a link-layer.  Copying
>DF bit is not prohibited for IPsec tunneling, but neither is it required
>for IPsec tunneling.

I think that, if not mandate copying the DF bit, the new drafts should
at least present the benefits of doing so and provide guidelines to
anyone who wants to have his implementation allow PathMTU. Or it could
be a separate document altogether.
- -Angelos

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQCVAwUBMv/vWr0pBjh2h1kFAQGX4gQAqWztVD0sSQ5Mn12W3Vq1IWg94XhA29Eo
X424Vc0se7CMe8SKaHoMlH6KekOazcI6wK/UPj3xnGPCJCNXf8jSf9/JjlONchTo
1jKch48MWPRC2NaeHpc05Zay9lIR7Ett7S22ZhrPHU1tOKCRlEWs+zxGdKo2T5QA
+rCt1gpl5NY=
=0AT2
-----END PGP SIGNATURE-----