> The Internet Service Providers (ISPs) must take action to drop long ICMP > packets in the backbone networks (any packet longer than 1499 bytes, at > least). This will break existing "good behaviour" legal systems and potentially disrupt MTU discovery proceedure. It isnt a feasible option without a lot of additional checks to the packet type etc, at which point with many routers the firewall rules involved turn into a performance based DoS on the core routers. Alan
- The "Mac DoS Attack," a Scheme for Blocking Intern... John Copeland
- Alan Cox
