-----Original Message----- From: Jonathan Brewer [mailto:jon.brewer(a)worldnet.att.net]
Hi Folks,
I've recently come up against the issue of some ISP routers in New Zealand which block ICMP. This creates an issue for some of our clients, who we deliver service to via GRE tunnels over a multi-hop wireless network.
My question for the list is, what are the known PMTUD "black holes" in New Zealand? Is there anyone out there unwilling to allow ICMP into their network? How do we make sure Path MTU Discovery works to all endpoints within NZ?
This was discussed quite a while back. Quite a few banks where rejecting ALL kinda of ICMP in/out of their networks (and breaking people looking at their sites via tunnels) (I don't know how many have/have not fixed it) There is nothing wrong with rejecting ICMP.. as long as you only reject the right types of ICMP you want to (echo-request only for example) The only way is to contact the sites which are broken and get them to fix it. For International Sites the same.. but there are a LOT of sites which are broken . Thanks Craig