EDNS0 allows dns packets >512 bytes. A workaround is discussed here:
http://lists.virus.org/fw1-0305/msg00433.html

Lars

-----Original Message-----
From: ckpt [mailto:[EMAIL PROTECTED]
Sent: 21. januar 2004 05:01
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Possible DNS protocol BUG in FW-1 NG FP3

On Tue, Oct 21, 2003 at 07:04:51AM +0200, Lars Troen wrote:
> Jose,
> If your dns servers are using EDNS0 (bind 9.2, w2k3dns) then yes, this
> is a known issue that has been discussed here before.

        Can you elaborate please ? I missed the earlier discussion.
        I just caught the error myself sniffing DNS - is there
        a solution or workaround ?

                                alan

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to