From 2d6f26a6c12ac9bce5afcca5a45f4ef21166920e Mon Sep 17 00:00:00 2001 From: bol-van Date: Sun, 6 Feb 2022 12:39:23 +0300 Subject: [PATCH] readme.eng: beautify --- docs/readme.eng.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/readme.eng.md b/docs/readme.eng.md index 5fe0b48..a6459a3 100644 --- a/docs/readme.eng.md +++ b/docs/readme.eng.md @@ -424,7 +424,7 @@ ipv4 : Linux allows to send ipv4 fragments but standard firewall rules in OUTPUT ipv6 : There's no way for an application to reliably send fragments without defragmentation by conntrack. Sometimes it works, sometimes system defragments packets. -Looks like kernels <4.16 have no simple way to solve this problem. Unloading of nf_conntrack module +Looks like kernels <4.16 have no simple way to solve this problem. Unloading of `nf_conntrack` module and its dependency `nf_defrag_ipv6` helps but this severely impacts functionality. Kernels 4.16+ exclude from defragmentation untracked packets. See `blockcheck.sh` code for example.