anubis has quit [Remote host closed the connection]
anubis has joined #glasgow
anubis has quit [Remote host closed the connection]
anubis has joined #glasgow
FFY00 has quit [Remote host closed the connection]
redstarcomrade has joined #glasgow
redstarcomrade has joined #glasgow
redstarcomrade has quit [Changing host]
FFY00 has joined #glasgow
anubis has quit [Remote host closed the connection]
joerg has quit [Ping timeout: 256 seconds]
joerg has joined #glasgow
FFY00 has quit [Ping timeout: 245 seconds]
bvernoux has joined #glasgow
<whitequark[cis]>
ewenmcneill: can you give me the iptables line i can just run >_<
<ewenmcneill[m]>
whitequark: What I'm using locally is: iptables -A OUTPUT -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1456 -d whitequark.org
<ewenmcneill[m]>
whitequark: at a guess you'd need to (a) change that to be the INPUT chain, and (b) possibly remove the "-d whitequark.org" (which I added as this is the only path that affects me that I know about).
<ewenmcneill[m]>
I forget if there's a "clamp MSS" option for iptables; I'm fairly sure "--set-mss" will force the MSS (max segment size) even if it's larger, which will also break things if it does increase it from the client request.
FFY00 has joined #glasgow
<whitequark[cis]>
I think there was a clamp MSS option
<whitequark[cis]>
--clamp-mss-to-pmtu or somehing
<ewenmcneill[m]>
--clamp-mss-to-pmtu yes. But it relies on Path MTU discovery working, which I'm not certain will work here.
<ewenmcneill[m]>
I can't find any other "set to min of this value and TCP session requested MSS" 😕
<whitequark[cis]>
test it?
<ewenmcneill[m]>
whitequark: I think that helped. I just tested from another system here (which hasn't had a local work around applied), and got a TLS connection this time.
<whitequark[cis]>
alright
<ewenmcneill[m]>
(Because it's MSS clamping, I can't test with "do not fragment" ICMP probing.)
cr1901 has quit [Quit: Leaving]
cr1901 has joined #glasgow
redstarcomrade has quit [Read error: Connection reset by peer]
siriusfox has quit [Ping timeout: 256 seconds]
siriusfox has joined #glasgow
FFY00 has quit [Ping timeout: 244 seconds]
ar-jan has joined #glasgow
cr1901_ has joined #glasgow
JimGM0UIN_ has joined #glasgow
feldim2425_ has joined #glasgow
daim has joined #glasgow
russss_ has joined #glasgow
cr1901 has quit [*.net *.split]
ewenmcneill[m] has quit [*.net *.split]
omnitechnomancer has quit [*.net *.split]
Foone has quit [*.net *.split]
feldim2425 has quit [*.net *.split]
marcan has quit [*.net *.split]
JimGM0UIN has quit [*.net *.split]
twix has quit [*.net *.split]
m42uko has quit [*.net *.split]
russss has quit [*.net *.split]
JimGM0UIN_ is now known as JimGM0UIN
russss_ is now known as russss
m42uko has joined #glasgow
Foone has joined #glasgow
ewenmcneill[m] has joined #glasgow
omnitechnomancer has joined #glasgow
marcan has joined #glasgow
omnitechnomancer has quit [Quit: Idle timeout reached: 172800s]