[40296] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: TCP session disconnection caused by Code Red?

daemon@ATHENA.MIT.EDU (Craig Partridge)
Mon Aug 6 15:56:06 2001

Message-Id: <200108061955.f76JtQQ02475@aland.bbn.com>
To: Alex Bligh <alex@alex.org.uk>
Cc: nanog@merit.edu
In-Reply-To: Your message of "Mon, 06 Aug 2001 20:50:09 BST."
             <7262579.997131009@[169.254.198.40]> 
Date: Mon, 06 Aug 2001 15:55:26 -0400
From: Craig Partridge <craig@aland.bbn.com>
Errors-To: owner-nanog-outgoing@merit.edu



RFC 1122 mandates that you query for a particular ARP
destination no more frequently than once per second.

RFC 1122 also notes a number of reasons why people may want to make
the positive ARP cache timeout long -- if one suppresses ARP queries
for that time, you'll have the situation where if a popular host goes
down for a period of time, it is effectively off the network for a long
period while waiting for ARP negative caches to timeout.  Probably
a bad idea.  Rate limiting, as RFC 1122 suggests, would seem to be much
better.

Craig

home help back first fref pref prev next nref lref last post