IPIPv6 TCP error with sha256

There is an IPIPv6 connection between an 750gr3 (6.42.7) and a 3011 (6.42.3).
I tried tho change the authentication protocol to sha256. I selected sha256 checkbox at the remote end ipsec proposal, (sha1 stayed checked too), and the local side at proposal I selected sha256 checkbox only (sha1 was deselected).
The tunnel reconected, I could ping the remote rb750gr3, but webfig was unacessible and winbox showed its reconnected to the remote routerboard but I cannot see any config or status info in winbox.
If I reselect sha1 and deselect sha256, everything ok again.

Up :slight_smile:

I upgraded to 6.43.1 (.2 on 750gr3) , there is still problem with IPIPv6 with SHA256.
The built in “clamp tcp to mss” mechanizm and maybee the MTU detection doesnt work. I have to manually lower the MSS (tried with 1340) with postrouting mangle rules at booth side, for the working TCP connection.

Please somebody check this!