Jan Just Keijser
2017-06-13 13:03:08 UTC
Hi,
1) compress
2) fragment
3) encrypt
and then in reverse on the receiving end, of course.
PMTUD if you tweak it manually and *with* openvpn you can use ICMP again over the tunnel itself!
HTH,
JJK
Hi Greetz Pippin,
Actually, that's a very nice update to my original picture!So, my first question is, how close am I?
At least the order of encryption/decryption and
compression/decompression makes no sense.
it's actually even weirder when you read the sources:compression/decompression makes no sense.
1) compress
2) fragment
3) encrypt
and then in reverse on the receiving end, of course.
Compression should be always done before encryption!
Regarding ICMP: Yes, PMTUD relies on ICMP, thus blocking ICMP is
generally a bad idea - why do you have this in place?
uhm, as Pippin stated, his firewall/router does this for him, whether he likes it or not; however, OpenVPN itself does not needRegarding ICMP: Yes, PMTUD relies on ICMP, thus blocking ICMP is
generally a bad idea - why do you have this in place?
PMTUD if you tweak it manually and *with* openvpn you can use ICMP again over the tunnel itself!
HTH,
JJK