nanog mailing list archives

Re: WIndows Updates Fail Via IPv6 - Update!


From: Mark Andrews <marka () isc org>
Date: Mon, 4 Mar 2019 10:16:13 +1100



On 4 Mar 2019, at 9:33 am, Stephen Satchell <list () satchell net> wrote:

On 3/3/19 1:04 PM, Mark Andrews wrote:
There are lots of IDIOTS out there that BLOCK ALL ICMP.  That blocks PTB getting
back to the TCP servers.

For those of us who are in the dark, "PTB" appears to refer to "Packet
Too Big" responses in ICMPv6.

Yes, some admins don't have fine-enough grain tools to block or throttle
specific types of ICMP, but that's the fault of the vendors, not the admins.

No, it is the fault of the admins.  They should be making it part of the purchasing
decision if they want to filter ICMP.  It’s not like selective filtering is a new idea.
It is well over 20 years old at this stage.  The amount of +20 year old equipment on the
net is minimal.  

That said modern OS’s don’t need other equipment to “protect" them from ICMP of any form.

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka () isc org


Current thread: