Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Fernando Gont
    (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954 rev.4
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954 rev.4

    At 08:35 a.m. 19/07/2005, Security Alert wrote:

    > Discussion of ip_pmtu_strategy
    > ----------------------------------
    >
    >The default value for ip_pmtu_strategy is 1. This allows for PMTU
    >discovery. Once the issue of this Security Bulletin has been
    >resolved via patches the ip_pmtu_strategy value of 1 will again be
    >the preferred setting for most situations.
    >
    >The ip_pmtu_strategy values of 0 and 3 set the PMTU to a fixed
    >size for destinations which are not on the local network.
    >
    >The ip_pmtu_strategy value of 0 sets the PMTU to 576 bytes.
    >Routers are required to handle packets of at least this size.
    >
    >The ip_pmtu_strategy value of 3 sets the PMTU to 1500 bytes. This
    >will generally result in more efficient transmission than the 576
    >byte PMTU. If it is known that the routers involved can handle a
    >1500 byte MTU the ip_pmtu_strategy value of 3 is preferred.


    These assumptions are completely wrong. Please read
    http://www.gont.com.ar/drafts/icmp-a...ainst-tcp.html

    The IPv4 minimum MTU is 68, and not 576. If you blindly send packets larger
    than 68 with the DF bit set, in the case there's an intermmediate with an
    MTU lower that 576, the connection will stall.

    576 is the minimum reassembly buffer size. That is the minimum packet size
    every *end-system* should be able to reassemble, and NOT the minimum packet
    size that can get to destination without fragmentation.

    Kindest regards,

    --
    Fernando Gont
    e-mail: fernando@gont.com.ar || fgont@acm.org






  2. #2
    Darren Reed
    (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954 rev.4
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954 rev.4

    In some mail from Fernando Gont, sie said:
    > The IPv4 minimum MTU is 68, and not 576. If you blindly send packets larger
    > than 68 with the DF bit set, in the case there's an intermmediate with an
    > MTU lower that 576, the connection will stall.


    And I think you can safely say that if you see any packets trying to
    indicate that the MTU of a link is "68" then you should ignore it.

    This came up some years ago in discussion about ... hmm... I think it
    was what made a good (or sensible) "fragmentation required" ICMP message.

    Ignoring quenches as a problem, if you try to send 10K of data to a
    box that has an MTU of 68, 1200+ packets are required vs less than 10
    for an ethernet MTU. The problem is 1200 packets require a lot more
    system time to send than 6 or 7. A different kind of DoS attack.

    I think it is reasonable to say anyone trying to advertise an MTU less
    than 576 has nefarious purposes in mind.

    oh, IPv6 guarantees a min. MTU of 1280.

    Lets just stop using IPv4 already.

    Darren

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics