Oh, you'll also be "pleased" to know that many networks will, at least some of the time, block frags. This will prevent an IPSEC VPN connection from coming up on a reliable basis because the keying requires packets that exceed the common MTU of the links used, and thus if frags cannot get through it won't negotiate.

This is a new one that I just started seeing with T-Mobile and is especially annoying -- it may be intentional or accidental, but it is definitely happening. That it OCCASIONALLY goes through implies it's not intentional, however.

Many "hostile" (e.g. open) WiFi access points are ALSO configured to drop frags (on purpose) which is VERY hostile as it prevents using a VPN through them.

