Hurricane Electric's IPv6 Tunnel Broker Forums Specific Topics => Questions & Answers => Topic started by: fenton on December 23, 2014, 08:49:02 AM

Title: MTU problems accessing
Post by: fenton on December 23, 2014, 08:49:02 AM
I have been having what are apparently MTU problems accessing Specifically, when I go to (which is used when logging in), the TCP connection opens, I send an SSL client hello, and then nothing (except keepalives). I just got off the phone with a bunch of people from Social Security and they confirmed that they are sending out a 1514-byte server hello in response, which I'm not receiving because of MTU, but their firewall engineer said they also aren't seeing an ICMP Packet Too Big message at the external interface to the firewall.

My tunnel is set up with a 1280-byte MTU, just to be conservative. Is there any way to be sure that the HE end of my tunnel is sending PTB messages as it should?
Title: Re: MTU problems accessing
Post by: fenton on January 14, 2015, 02:35:42 PM
After working with SSA and Hurricane Electric support, we discovered that SSA had blocked the IPv6 network of the router from which the Packet Too Big messages were being sent. The block resulted from a DDoS incident last summer, and has been resolved.

Thanks to both SSA and HE for their help resolving this.