Firewall Wizards mailing list archives

Re: Transparent proxies and PMTUD on the (WWW) server side


From: "Marcus J. Ranum" <mjr () ranum com>
Date: Tue, 26 Aug 2003 17:22:43 -0400


If an ALG supports transparent proxying, enables PMTUD, and does not intercept ICMP must fragment, the ALG is broken. 
File a high priority trouble ticket with your vendor.

If an ALG understands PMTUD and ICMP it's not an ALG, it's a packet
filter masquerading as a proxy. All that stuff is totally below application
space.

mjr.


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: