nanog mailing list archives

Re: DDoS using port 0 and 53 (DNS)


From: sthaug () nethelp no
Date: Wed, 25 Jul 2012 08:13:20 +0200 (CEST)

The port number of the Layer 4 connection cannot be determined without
executing IP fragment reassembly in that case.    Routers normally
reassemble fragments they receive, if possible.

No, routers normally do *not* reassemble fragments. This is typically
done by hosts and firewalls.

Steinar Haug, Nethelp consulting, sthaug () nethelp no


Current thread: