-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Fri, 2016-11-18 at 15:41 -0500, [email protected] wrote:

> Did you do anything to specifically identify Yahoo's routers as the
> offenders?

> Hint: If there's a tunnel in the path, it will be *your* end of the
> tunnel
> that sends back the "can't frag" ICMP.  So the filtering is happening
> somewhere
> between your end of the tunnel and you.

This happens very early in the TLS handshake. The tcp (syn,syn-ack,ack)
handshake works; my system sends a 286 byte TLS client hello, and the
response to that will be a bunch of full size packets from Yahoo with
the certificate, etc. The *far* end of my tunnel will be sending the
icmpv6 "packet too big" back to Yahoo.


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)

iEYEAREKAAYFAlgvbDcACgkQL6j7milTFsEI/QCdFDIewzPza2v7vqQVhqfq1iZS
tv0An3gJgoPqYx1A0Gx9W2o1tTkKWFOZ
=qCzk
-----END PGP SIGNATURE-----



_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to