[OpenAFS] MS ISA-Server

Ulf Ziemann ulf.ziemann@prodesigncad.de
Wed, 31 Mar 2004 08:22:41 +0200


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

I have a network with 2 OpenAFS server version 1.2.11.
This net was connected with a second network over IpSec-VPN.

In the other net are a Linux and a Windows client. No problems at all.

Now cames 2 MS ISA server.
They tunnel the traffic thru the the IpSec-VPN.
Normal traffic passes the 2 tunnels (IMAP/SMTP, Windows shares, FTP,...)

Only AFS is the problem.

I can get an token. But I can't see something under /afs .
The process is blocked for a long time.
No messages in /var/log/messages.

It seems, the MTU are to large for the packets.
I set the MTU on the servers and on the linux client to 1000 and
restarted the afs server.
Ping with to large size now don't work.

Now the "ls /afs" returns immediately, but with an empty answer.

Network Monitor on the ISA says, the AFS-Server would always send with
an MTU from 14XX bytes with fragment=false and so it remove the packet....

How can I change the MTU for the afs? Are any other hints available?

Ulf Ziemann

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFAamOp8cc/MGdmyloRAvMKAJ9SmlIeylw30P/mjjjOtlyFRaOTUwCglN/n
3HPO8pQxXH+1pSu2G+9jdao=
=DrMq
-----END PGP SIGNATURE-----