Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

2
  • Hi, thank you for the tip! Just to note for others, you also need -t mangle. I also used --tcp-flags SYN,RST SYN (as suggested in the man page, although I think it's redundant). I also left off the -o as I do DNAT as well in this box and I'm just guessing but maybe the issue could affect incoming connections as well. So the full command that worked for me was iptables -t mangle -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1452. Commented Nov 21, 2012 at 18:49
  • @Kevin Right, I forgot to add in the -t mangle. That definitely needs to be there. Not sure about the --tcp-flags. Updated the answer to add in the missing mangle. Commented Nov 27, 2012 at 16:13