Community discussions

 
User avatar
amt
Long time Member
Long time Member
Topic Author
Posts: 526
Joined: Fri Jan 16, 2015 2:05 pm

eoip tunnel mtu and pppoe serverr

Mon Apr 27, 2015 11:47 am

Hi,

I need help. I have pppoe server and sending all pppoe connections over eoip tunnels. but have some questions, I set the mtu size auto and eoip tunnels set them as 1458 but at the client side we use both mikrotik and ubnt device so ubnt use 1492 for mtu and mru size. mikrotik use 1480.
at pppoe server they all are default max mtu and mru 1480 and mrrru is disabled. so what should i do for mtu size ?


Thanks.
Last edited by amt on Sat May 16, 2015 11:21 pm, edited 1 time in total.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 2946
Joined: Tue Feb 25, 2014 12:49 pm
Location: Capalbio, Tuscany, Italy

Re: eoip tunnel mtu and pppoe server

Mon Apr 27, 2015 9:08 pm

Hi,

I need help. I have pppoe server and sending all pppoe connections over eoip tunnels. but have some questions, I set the mtu size auto and eoip tunnels set them as 1458 but at the client side we use both mikrotik and ubnt device so ubnt use 1492 for mtu and mru size. mikrotik use 1480.
at pppoe server they all are default max mtu and mru 1480 and mrrru is disabled. so what should i do for mtu size ?


Thanks.
For optimal configuration on mix devices:
put pppoe-server directly on EoIP, do not use any bridge,
but obviously you put eoip on bridge on other side, if needed...
do not assign any IP to the EoIP ends or to any interface on pppoe-server or client

Assing on both eoip ends auto mtu, when present set on the bridge the auto-mtu,
enable clamp tcp mss if routeros => 6.28
leave don't fragment to off
with encrypion DISABLED on pppoe-server profile, set mtu and mru to 1492, MRRU to 1600
with encrypion ENABLED on pppoe-server profile, set mtu and mru to 1480, MRRU to 1600
(if on other side of pppoe-server the client not are one CPE but is one pppoe-client inside one Windows machine, the MRRU must be 1614)

on client side you must put the same config as server!

about ONLY pppoe-server:

if you use cambium devices, do not use more than 1480 for mtu/mru and do not enable mrru or encryption, it support only chap and pap

if you use ubiquity devices, do not use mrru and set mtu/mru to 1492, disable encryption if possible.

if you use ligowave/deliberant devices DO NOT put more than 1492 MTU/MRU and DO NOT activate MRRU...

if you want mix mikrotik with ubiquiti toys leave all the pppoe-server value to it's default 1480 and activate 1600 mrru

if you want mix mikrotik with cambium slug set mtu/mru to 1492 and disable mrru & the encryption

if you want mix mikrotik with ligowave/deliberant buggy software [yes, more than routeros ;)) ] set mtu/mru to NO MORE THAN 1492 and ABSOLUTELY disable mrru
I'm Italian, not English. Sorry for my imperfect grammar.
 
User avatar
amt
Long time Member
Long time Member
Topic Author
Posts: 526
Joined: Fri Jan 16, 2015 2:05 pm

Re: eoip tunnel mtu and pppoe server

Tue Apr 28, 2015 11:38 am

Hi rextended,

thanks for your help..

"put pppoe-server directly on EoIP, do not use any bridge"
i set pppoe-server interface eoip tunnel.

"enable clamp tcp mss if routeros => 6.28"
i set clamp tcp mss enable but ros 6.27 both side

"with encrypion DISABLED on pppoe-server profile, set mtu and mru to 1492, MRRU to 1600
"with encrypion ENABLED on pppoe-server profile, set mtu and mru to 1480, MRRU to 1600

I let all protocols default only use mpls and ipv6 disabled. do i need set encrypion enabled ? cause mikrotik and ubnt mixed on the system.

"if you want mix mikrotik with ubiquiti toys leave all the pppoe-server value to it's default 1480 and activate 1600 mrru"
and this side i set pppoe-server mtu and mru auto. and mrru disabled. and also at profile change tcp mss enabled.

now im going to just set pppoe server side mtu/mru 1480 and mrru 1600 ? or more ?


Thanks again.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 2946
Joined: Tue Feb 25, 2014 12:49 pm
Location: Capalbio, Tuscany, Italy

Re: eoip tunnel mtu and pppoe server

Tue Apr 28, 2015 11:56 am

Hi rextended,
>>>"put pppoe-server directly on EoIP, do not use any bridge"
>>>i set pppoe-server interface eoip tunnel.
perfect

>>>"enable clamp tcp mss if routeros => 6.28"
>>>i set clamp tcp mss enable but ros 6.27 both side
because on 6.28 are fixed one bug about clamp tcp mss, read the changelog

>>>I let all protocols default only use mpls and ipv6 disabled. do i need set encrypion enabled ?
>>>cause mikrotik and ubnt mixed on the system.
the right choice is to NOT activate the encryption, wpa2 + aes-ccm + good password are strong enought...

>>>"if you want mix mikrotik with ubiquiti toys leave all the pppoe-server value to it's default 1480 and activate 1600 mrru"
>>>and this side i set pppoe-server mtu and mru auto. and mrru disabled. and also at profile change tcp mss enabled.
for compatibility with ubunto, do not leave "auto" on pppoe-server, only on eoip and, if needed, on the bridge.

>>>now im going to just set pppoe server side mtu/mru 1480 and mrru 1600 ? or more ?
no more, just this two.

By.
I'm Italian, not English. Sorry for my imperfect grammar.
 
User avatar
amt
Long time Member
Long time Member
Topic Author
Posts: 526
Joined: Fri Jan 16, 2015 2:05 pm

Re: eoip tunnel mtu and pppoe server

Sat May 16, 2015 11:23 pm

great....

i will do them. but Im not thinking to upgrade ros to 6.28 cause there are no good news about it :) i think we will wait 6.29...

thanks rextended.
 
User avatar
omidkosari
Trainer
Trainer
Posts: 616
Joined: Fri Sep 01, 2006 4:18 pm
Location: Iran , Karaj
Contact:

Re: eoip tunnel mtu and pppoe server

Sun Nov 08, 2015 1:09 pm


enable clamp tcp mss if routeros => 6.28
In this situation there is no tcp goes through tunnel , so is it useful to enable 'clamp tcp mss' at all ?
MTCNA , MTCRE, MTCWE, Mikrotik Certified Trainer
 
User avatar
amt
Long time Member
Long time Member
Topic Author
Posts: 526
Joined: Fri Jan 16, 2015 2:05 pm

Re: eoip tunnel mtu and pppoe server

Sun Apr 10, 2016 12:41 am


enable clamp tcp mss if routeros => 6.28
In this situation there is no tcp goes through tunnel , so is it useful to enable 'clamp tcp mss' at all ?

What you prefer ?

Who is online

Users browsing this forum: No registered users and 96 guests