On Sun, Jan 23, 2022 at 05:10:42PM +0100, james list wrote:
> I suspect the current Cisco implementation does not change MSS because the
> syn-ack does not contain the MSS option.

If there is no MSS option, nothing can be adjusted - one would need extra
code to *add* such an option, which is more complex than "change one 
number and adjust the checksum".

So, get your firewall vendor to fix their SYN-ACK-spoofing code.

