MSS Clamping

Started by MagikMark, December 13, 2023, 12:21:23 AM

Previous topic - Next topic
I'm considering MSS value 1448.  I just would like to confirm that I understood it right what is indicated on the "help".  It would deduct a value of 40 on the MSS field.  So, the value that I need to put on the field is MSS 1488.  Is that right?

You have to subtract it from the MTU.

If your MTU is 1500 bytes and you have IPv6 TCP packets that are 60 bytes (IPv6 + TCP header size), your MSS would be 1440 bytes.
Hardware:
DEC740

Monviech, the help text in the UI explicitly states that OPNsense would be doing that subtraction and that you should put the MTU, not the MSS, into the field which is confusingly labelled "MSS". The OP just wants to make sure the help text is actually correct. Go check for yourself ;)
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

@Patrick You are right, that help text sounds really confusing.

I would rather use "Firewall: Settings: Normalization" and create a rule for the interface there instead of putting a value in the interface MSS field.

Hardware:
DEC740