[43837] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Digital Island sponsors DoS attempt?

daemon@ATHENA.MIT.EDU (Bob K)
Fri Oct 26 14:45:37 2001

Date: Fri, 26 Oct 2001 14:44:46 -0400 (EDT)
From: Bob K <melange@yip.org>
To: "Quibell, Marc" <mquibell@icn.state.ia.us>
Cc: nanog@merit.edu
In-Reply-To: <EF4A9841BCC9D5119E28009027923DF0137073@yosemite.icn.state.ia.us>
Message-ID: <Pine.BSF.4.21.0110261433260.1593-100000@pi.yip.org>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu


On Fri, 26 Oct 2001, Quibell, Marc wrote:

> Finally, I do not believe PMTU uses pings to discover the PMTU. I believe it
> uses TCP or UDP packets at the layers above IP, and it DOES use "ICMP Packet
> Too big" responses (from the receiver) to cut it's packet size. So in
> reality, a router blocking ICMP from being routed through can still send
> these ICMP messages PMTU needs. Is this how you understand it?

Don't forget that routers or hosts beyond (from the point of view of the
host attempting PMTU) your ICMP-blocking router may have smaller MTUs than
the norm and may be trying to send ICMP errors back...

-- 
Bob <melange@yip.org> | We're all wrong.



home help back first fref pref prev next nref lref last post