ongoing problems with broken Path-MTU-discovery on servers at cvshome.or

From: Greg A. Woods
Subject: ongoing problems with broken Path-MTU-discovery on servers at
Date: Wed, 22 Nov 2000 15:31:21 -0500 (EST)

Can someone please clue in the appropriate people that there's a very
SERIOUS problem with the servers at and/or
Both the anonymous CVS server, and the anonymous FTP server are failing
to do proper Path-MTU-discovery (probably because of a broken or
mis-configured firewall or router somewhere between those machines and folks have assured me that they do not filter
anything, and I know they're at least partly right since I can FTP to
other clients just fine.  The problem can only be at

This has been broken for several months now.

Until this is fixed everyone (such as myself) who resides behind a
router with a smaller-than-1500-byte MTU will continue to be unable to
either check out the CVS source with CVS, or to retrieve files from the
FTP server.


You must *NOT* ever filter, drop, or otherwise inhibit valid ICMP error
messages since doing so breaks the correct operation of TCP.  ICMP is a
very critical part of the TCP/IP protocol suite and it is absolutely
necessary that it function correctly for any server doing PMTUD.  At the
bare minimum PLEASE immediately disable Path-MTU-discovery on your
servers until the errant firewall/router/whatever is found and fixed!

                                                        Greg A. Woods

+1 416 218-0098      VE3TCP      <address@hidden>      <robohack!woods>
Planix, Inc. <address@hidden>; Secrets of the Weird <address@hidden>

