Firewall Wizards mailing list archives

Re: Cisco PIX bug, discussions (lenghty)


From: Eric Vyncke <evyncke () cisco com>
Date: Fri, 28 Aug 1998 23:20:25 +0200

At 15:00 26/08/98 -0500, Aleph One wrote:
Just in case everyone has forgotten:

RFC 1859: Security Considerations for IP Fragment Filtering
ftp://ftp.isi.edu/in-notes/rfc1858.txt

Just for info, this RFC 1858 is implemented in IOS since a couple
of years now. This is the reason why newtear (teardrop but
within the TCP header) is not working accross a router.

-eric


Aleph One / aleph1 () dfw net
http://underground.org/
KeyID 1024/948FD6B5 
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01 

Eric Vyncke      
Technical Consultant               Cisco Systems Belgium SA/NV
Phone:  +32-2-778.4677             Fax:    +32-2-778.4300
E-mail: evyncke () cisco com          Mobile: +32-75-312.458



Current thread: