!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

913 Members
Declaratively manage your switching, routing, wireless, tunneling and more.269 Servers

Load older messages


SenderMessageTime
10 Feb 2026
@autiboy:matrix.mautiweb.netAutiboy changed their profile picture.02:59:31
@autiboy:matrix.mautiweb.netAutiboy changed their profile picture.03:00:17
@mon:tchncs.depneumatic changed their display name from ribosomerocker to pneumatic.10:28:51
@acidbong:envs.netAcid Bong joined the room.12:09:45
@acidbong:envs.netAcid Bongwhy does Dnsmasq service add a user and a group, but not use them?12:36:02
@acidbong:envs.netAcid Bongoh, it uses a CLI argument, got it12:42:28
@nazarewk:matrix.orgkdn

got a weird issue after setting up VLANs over ~7 different devices: when connected through AP that has VLAN 3547 some (eg: facebook works, hacker news dont) of the SSL (HTTPS) handshakes keep timing out and are retried in a loop, connecting to the same switch over ethernet works just fine

there is basically: AP (EAP773) -> zyxel switch -> mikrotik switch -> openwrt router (LAN on 3547)

13:12:45
@nazarewk:matrix.orgkdnthe working/not working set of domains seem to be consistent across devices (laptop, phone etc.)13:13:23
@molly:matrix.flyingcircus.ioMolly Millerthat sounds like it could be an mtu problem13:14:53
@nazarewk:matrix.orgkdnI don't think I have modified it anywhere, should be default 1500 all the way13:16:26
@nazarewk:matrix.orgkdnis anything (VLANs?) in such setup chewing through MTU?13:16:58
@molly:matrix.flyingcircus.ioMolly Milleri don't think so, i haven't ever seen similar problems when working with vlans, but tls handshakes timing out weirdly is often a symptom of mtu problems13:21:46
@molly:matrix.flyingcircus.ioMolly Millerthe sites that do and don't work, are there any patterns to those that do or those that don't?13:22:23
@molly:matrix.flyingcircus.ioMolly Millerespecially IPv4/IPv613:22:26
@me:m4rc3l.deMarcel Otherwise you could trz to use traceroute (or tracepath) to check if there is a difference in the mtu to the target host. I always forget if traceroute or tracepath also determinates the mtu. 13:25:12
@nazarewk:matrix.orgkdnwill check, I could issue pings of specific sizes to pinpoint at which connection the issue occurs?13:26:47
@molly:matrix.flyingcircus.ioMolly Milleryes, that's an option13:30:16
@nazarewk:matrix.orgkdn so curl -v https:// works for facebook.com, doesn't for news.ycombinator.com & nc.nazarewk.pw (my Hetzner nextcloud) 13:32:48
@nazarewk:matrix.orgkdn ping -s XXXX nc.nazarewk.pw seems to work fine between 1200 and 1700 13:34:56
@nazarewk:matrix.orgkdn * ping -s XXXX nc.nazarewk.pw seems to work fine between 1200 and 1700 over IPv6, let's try other options 13:35:10
@nazarewk:matrix.orgkdn ping -4 -s XXXX nc.nazarewk.pw works for 1460, doesn't for 1470, let's try narrowing it down 13:36:24
@nazarewk:matrix.orgkdn 1468 is the last one that works, 1469 doesn't 13:37:12
@nazarewk:matrix.orgkdnyeah, it's the same for router's IP13:46:48
@magic_rb:matrix.redalder.orgmagic_rbYeah last time i did it its just trial and error seeing what mtu works or not13:47:39
@magic_rb:matrix.redalder.orgmagic_rbIf you know its 1468 then increase your routers uplink mtu to 153213:47:58
@magic_rb:matrix.redalder.orgmagic_rbDo you happen to be going over pppoe? That number seems familiar to me (i am going over pppoe)13:48:15
@magic_rb:matrix.redalder.orgmagic_rbIdeally your internal network mtu remains at 150013:48:31
@nazarewk:matrix.orgkdnno, I'm not going over PPPoE, the connectivity fails over LAN address space too (from Wifi AP to the router over 2 switches)13:50:19
@nazarewk:matrix.orgkdnI'm trying to find some MTU settings on AP (EAP773) or zyxel XGS1250-12, but so far no luck13:50:42
@nazarewk:matrix.orgkdnthat seems useful (from Kagi Assistant): Why 1468 Bytes? Normal MTU: 1500 bytes Your effective MTU: 1468 + 28 (ICMP/IP headers) = 1496 bytes Missing: 4 bytes = exactly the size of a VLAN 802.1Q tag 1 When VLAN tagging is added, frames grow from 1500 to 1504 bytes. If any device in the path doesn't account for this, it causes fragmentation or drops.13:51:23

Show newer messages


Back to Room ListRoom Version: 6