Re: [6MAN] UDP+Fragmentation

2013-09-26 Thread Fernando Gont
On 09/26/2013 02:02 PM, Warren Kumari wrote: >>> There has also been discussion that for things like routers you >>> can just do X to protect the device control plane / only care >>> about traffic directed to the device itself. >> >> Agreed. But, isn't that orthogonal to the discussion regarding >

Re: [6MAN] UDP+Fragmentation (was: "Deprecate")

2013-09-26 Thread Warren Kumari
On Sep 25, 2013, at 3:38 PM, Fernando Gont wrote: > On 09/25/2013 02:32 PM, Warren Kumari wrote: >>> >>> Unless you have a very sloppy IPv6 implementation (that does not >>> enforce limits on the maximum number of queued fragments), an >>> attacker will only be able to DoS communication instanc