Firewall Wizards mailing list archives

Re: A fun smackdown...


From: "Marcus J. Ranum" <mjr () ranum com>
Date: Fri, 20 May 2005 22:02:50 -0400


How about excessive ICMP filtering breaking path MTU discovery?

Another perfect example of a bunch of egg-heads in the IETF
coming up with a mechanism for doing something that
completely ignored existing implementations of security
systems - and breaks as a result. The PMTU discovery
mechanism, using ICMP, was moronic design from the get-go.

mjr.


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: