Re: Fragmentation-related security issues

2012-01-28 Thread Florian Weimer
* Fernando Gont: There are existing deployments which effectively filter ICMPv6 traffic. They should know better.. what can I say? These people generally know what they are doing. Some of them do so explicitly, others simply to do not broadcast incoming IPv6 ICMP traffic to all cluster

Re: Fragment ID generation and Flow Label generation

2012-01-28 Thread Fernando Gont
On 01/27/2012 07:13 PM, Fernando Gont wrote: On 01/27/2012 06:08 PM, Philip Homburg wrote: So any system that is too busy to keep destination cache entries for a long time will effectively send fragments with a random number. There are always tradeoffs in the IP-ID generation algorithms. If

Re: Fragmentation-related security issues

2012-01-28 Thread Fernando Gont
Florian, On 01/28/2012 11:26 AM, Florian Weimer wrote: There are existing deployments which effectively filter ICMPv6 traffic. They should know better.. what can I say? These people generally know what they are doing. TCP relies on PMTUD, so how can you possibly state that they know what