eLearn via VPN iBurst : Not Working : help

AdVerbatim

New Member
Joined
Mar 19, 2009
Messages
3
Reaction score
0
Location
Durban
Hello All

I've been registered since the begging of the month on a "Linux Security"
course and I need to participate in online Labs via a VPN connection backto
the online labs.

The OS and client that I have to use is Linux and OpenVPN. The
connectivity pack (OpenVPN) and credentials where supplied, and confirmed
to be fully operational on the above linux installation when connected via
Telkom ADSL line. Other local participant's that use ADSL and 3G also have
no problems.

The problem now is when I connect to the eLabs via VPN and iBurst, I can
'ping' other machines inside the tunnel but any thing larger say a
Remote Desktop every thing comes to a grinding halt (time outs).

From my reading up on VPN it seems to be a classic MTU fragmentation issue
and my current understanding of VPN still leaves much to be desired.

I am aware of the MTU settings mention previously mentioned in these forums
eg. 1392 for browsing and 1364 for VPN. But the 1364 setting me thinks is for
when one has direct control/access to the VPN server, not a VPN server outside
your domain and control.

If any one can offer advice or suggestions on how I might cure this problem it
would be very much appreciated.

I also connect via UTD modem and PPPoE, and have no problems when using
it with XP or Linux. I also have clear sight to the tower and full signal strength,
and 'pinging' the 'iburstgroup' from both XP and Linux averages about 100ms.


Thx for any reply's...
 
...it worked best for me using the default MTU of 1500, keep in mind that there seems not to be any consistency on the iBurst network and each tower is set-up differently to the next - if you look at the routing and shaping it could also affect your connection.

iBurst seems to make use of various backbone providers with different levels of connectivity... (port)

It would be best to approach someone that has in depth knowledge of the tower you are utilising or perhaps approach Shaun the iBurst rep.

I utilise the Gardens tower (Cape Town - CBD) and at times the only thing I can use it for is browsing; not even mail is allowed through and RDC's are totally blocked.

Regards

Mike

Advice: Do not use iBurst - you will only frustrate youself.
 
Last edited:
Thx for coming to me who.is.michael

When you talk of a MTU 1500, I assume you are referring to the MTU of the TUN dev.

I've tried to bring it down with '--fragment' and '--mssfix' my side but the server on the
other side through its 'toy's out the cot', did not like it at all. Will continue over the
weekend experimenting, to see if I come right.

iBurst support knows about my problem, I emailed them three evenings ago.

It's a pity they are unable to give me answer one way or the other.

I might have to retire my old faithfull beige modem after five or six years or so, and
have a serious look at a 'Huawei E220 USB' from from one of the other providers. As I
need to continue with eLearning studies, and improve my skills for work reasons.
 
Hi AdVerbatim

Please set your MTU size to 1352. This is the stadard size for VPN tunneling.

Thanks


Cheers

Shaun
 
Hi Saun

Thanks for coming back to me here and via email...

Unfortunately none of the suggestions worked. After much experimenting
I discovered one thing that did work with mt OpenVPN client, I add a
command line switch "--mssfix 1358". I derived at the figure while watching
my UDP packet size been returned via my Ethernet port (eth0), the final
size I settled on was 1391 and perhaps not optimal but it now works...
 
Top
Sign up to the MyBroadband newsletter
X