On Fri, Mar 01, 2002 at 02:04:31PM -0500, Yan Seiner wrote: > James A. Pattie wrote: [snip] > No joy. That was one of the things I first thought of, and found on > deja.... > > Any other ideas?
try getting the TCPMSS target, and add a rule: iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu maybe it'll work. -- Zinx Verituse