nanog mailing list archives

RE: Digital Island sponsors DoS attempt?


From: Bob K <melange () yip org>
Date: Fri, 26 Oct 2001 14:44:46 -0400 (EDT)


On Fri, 26 Oct 2001, Quibell, Marc wrote:

Finally, I do not believe PMTU uses pings to discover the PMTU. I believe it
uses TCP or UDP packets at the layers above IP, and it DOES use "ICMP Packet
Too big" responses (from the receiver) to cut it's packet size. So in
reality, a router blocking ICMP from being routed through can still send
these ICMP messages PMTU needs. Is this how you understand it?

Don't forget that routers or hosts beyond (from the point of view of the
host attempting PMTU) your ICMP-blocking router may have smaller MTUs than
the norm and may be trying to send ICMP errors back...

-- 
Bob <melange () yip org> | We're all wrong.



Current thread: