CoMo
Commodore
- Registriert
- Dez. 2015
- Beiträge
- 4.878
Hallo,
Problem im Titel nicht erlaubt, deshalb musste ich das so seltsam schreiben:
ich kann hier aus meinem Heimnetzwerk hinter der OPNsense https://wiwo.de nicht via IPv6 aufrufen:
IPv4 funktioniert:
Möglicherweise ein Path MTU / MSS Problem? MSS Clamping auf LAN/WAN habe ich testweise von 1432 auf 1360 runtergestellt. Was könnte noch das Problem sein?
Problem im Titel nicht erlaubt, deshalb musste ich das so seltsam schreiben:
🤔Der Titel ist nicht aussagekräftig. Bitte vermeide wenig aussagekräftige Phrasen wie „Hilfe“, „Problem“, „geht nicht“ und doppelte Satzzeichen.
ich kann hier aus meinem Heimnetzwerk hinter der OPNsense https://wiwo.de nicht via IPv6 aufrufen:
Code:
❯ curl -6 -v https://www.wiwo.de > /dev/null
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Host www.wiwo.de:443 was resolved.
* IPv6: 2603:1061:14:67::1
* IPv4: (none)
* Trying [2603:1061:14:67::1]:443...
* Connected to www.wiwo.de (2603:1061:14:67::1) port 443
* ALPN: curl offers h2,http/1.1
} [5 bytes data]
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
} [512 bytes data]
* CAfile: /etc/ssl/certs/ca-certificates.crt
* CApath: /etc/ssl/certs
{ [5 bytes data]
* TLSv1.3 (IN), TLS handshake, Server hello (2):
{ [88 bytes data]
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
} [1 bytes data]
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
} [512 bytes data]
0 0 0 0 0 0 0 0 --:--:-- 0:00:36 --:--:-- 0^C
IPv4 funktioniert:
Code:
❯ curl -4 -v https://www.wiwo.de > /dev/null
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Host www.wiwo.de:443 was resolved.
* IPv6: (none)
* IPv4: 150.171.109.104
* Trying 150.171.109.104:443...
* Connected to www.wiwo.de (150.171.109.104) port 443
* ALPN: curl offers h2,http/1.1
} [5 bytes data]
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
} [512 bytes data]
* CAfile: /etc/ssl/certs/ca-certificates.crt
* CApath: /etc/ssl/certs
{ [5 bytes data]
* TLSv1.3 (IN), TLS handshake, Server hello (2):
{ [88 bytes data]
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
} [1 bytes data]
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
} [512 bytes data]
* TLSv1.3 (IN), TLS handshake, Server hello (2):
{ [155 bytes data]
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
{ [19 bytes data]
* TLSv1.3 (IN), TLS handshake, Certificate (11):
{ [3669 bytes data]
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
{ [264 bytes data]
* TLSv1.3 (IN), TLS handshake, Finished (20):
{ [52 bytes data]
* TLSv1.3 (OUT), TLS handshake, Finished (20):
} [52 bytes data]
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / prime256v1 / RSASSA-PSS
* ALPN: server accepted h2
* Server certificate:
* subject: CN=www.wiwo.de
* start date: Jun 16 00:00:00 2026 GMT
* expire date: Dec 16 23:59:59 2026 GMT
* subjectAltName: host "www.wiwo.de" matched cert's "www.wiwo.de"
* issuer: C=US; O=DigiCert Inc; OU=www.digicert.com; CN=GeoTrust TLS RSA CA G1
* SSL certificate verify ok.
* Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* Certificate level 1: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
} [5 bytes data]
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://www.wiwo.de/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: www.wiwo.de]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.5.0]
* [HTTP/2] [1] [accept: */*]
} [5 bytes data]
> GET / HTTP/2
> Host: www.wiwo.de
> User-Agent: curl/8.5.0
> Accept: */*
>
{ [5 bytes data]
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
{ [265 bytes data]
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
{ [265 bytes data]
* old SSL session ID is stale, removing
{ [5 bytes data]
< HTTP/2 200
< date: Wed, 23 Sep 2026 12:09:04 GMT
< content-type: text/html
< vary: Origin, Accept-Encoding
< hmg-page-cache: hit
< etag: "2b17918866ed5671f95795c174d59dfed098b09635217f625e2e6b581d16eb4e"
< last-modified: Wed, 23 Sep 2026 12:01:42 GMT
< cache-control: public, s-maxage=60, max-age=1, stale-while-revalidate=30, stale-if-error=86400
< x-azure-ref: 20260923T120904Z-15d589cbfbd5rgmjhC1BER5e5s0000003v6g0000000038zb
< x-cache: TCP_REVALIDATED_HIT
< x-fd-int-roxy-purgeid: 0
< x-cache-info: L2_T1
<
{ [5549 bytes data]
100 1858k 0 1858k 0 0 4049k 0 --:--:-- --:--:-- --:--:-- 4058k
* Connection #0 to host www.wiwo.de left intact
Möglicherweise ein Path MTU / MSS Problem? MSS Clamping auf LAN/WAN habe ich testweise von 1432 auf 1360 runtergestellt. Was könnte noch das Problem sein?