Likes Likes:  0
Resultaten 1 tot 6 van de 6
Geen
  1. #1
    Darren Reed
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954

    In some mail from Fernando Gont, sie said:
    >
    > At 07:25 p.m. 20/07/2005, Darren Reed wrote:
    >
    > >In some mail from Fernando Gont, sie said:
    > > > The IPv4 minimum MTU is 68, and not 576. If you blindly send packets

    > > larger
    > > > than 68 with the DF bit set, in the case there's an intermmediate with an
    > > > MTU lower that 576, the connection will stall.

    > >
    > >And I think you can safely say that if you see any packets trying to
    > >indicate that the MTU of a link is "68" then you should ignore it.

    >
    > Yes. But what about 296?
    >

    ....
    > >I think it is reasonable to say anyone trying to advertise an MTU less
    > >than 576 has nefarious purposes in mind.

    >
    > There are still some radio links with MTUs of 296 bytes.


    Go search with google....people still actively use smaller MTUs.

    What do you do? Where do you draw the line in the sand?

    Darren

  2. #2
    Fernando Gont
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954

    At 07:25 p.m. 20/07/2005, Darren Reed wrote:

    >In some mail from Fernando Gont, sie said:
    > > The IPv4 minimum MTU is 68, and not 576. If you blindly send packets

    > larger
    > > than 68 with the DF bit set, in the case there's an intermmediate with an
    > > MTU lower that 576, the connection will stall.

    >
    >And I think you can safely say that if you see any packets trying to
    >indicate that the MTU of a link is "68" then you should ignore it.


    Yes. But what about 296?



    >Ignoring quenches as a problem, if you try to send 10K of data to a
    >box that has an MTU of 68, 1200+ packets are required vs less than 10
    >for an ethernet MTU. The problem is 1200 packets require a lot more
    >system time to send than 6 or 7. A different kind of DoS attack.


    ?
    That of "more system time" required was listed as one of the effects of the
    PMTUD attack in one of the e-mails I sent today.
    Not sure what you are saying about ICMP Source Quenches....



    >I think it is reasonable to say anyone trying to advertise an MTU less
    >than 576 has nefarious purposes in mind.


    There are still some radio links with MTUs of 296 bytes.


  3. #3
    Casper.Dik@Sun.COM
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954


    >> There are still some radio links with MTUs of 296 bytes.

    >
    >Go search with google....people still actively use smaller MTUs.
    >
    >What do you do? Where do you draw the line in the sand?


    Well, the minimum requirement for "you must be able to reassemble this"
    is 576; so you use PMTU until you go as low as 576 at which point you
    stop using the DF bit.

    Casper

  4. #4
    Dennis Lubert
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954

    At 00:09 20.07.2005, Fernando Gont wrote:

    >The IPv4 minimum MTU is 68, and not 576. If you blindly send packets
    >larger than 68 with the DF bit set, in the case there's an intermmediate
    >with an MTU lower that 576, the connection will stall.
    >
    >576 is the minimum reassembly buffer size. That is the minimum packet size
    >every *end-system* should be able to reassemble, and NOT the minimum
    >packet size that can get to destination without fragmentation.


    To be completely correct
    <quote RFC 791>
    Every internet module must be able to forward a datagram of 68 octets
    without further fragmentation. This is because an internet header my be up
    to 60 octets, and the minimum fragment is 8 octets.
    Every internet destination must be able to receive a datagram of 576 octets
    either in one piece or in fragments to be reassembled.
    </quote>

    So 576 is the minimum packet size you can get to a destination without
    fragmentation


    Carpe quod tibi datum est


  5. #5
    Dana Hudes
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954

    you will find a range of MTU sizes in radio links of various sorts which
    is not just 802.11 but also cellular including GPRS CDMA and WCDMA.
    Now, in many instances there is a proxy between the mobile station and the
    public network. In fact I wrote a powerpoint presentation summarizing such
    a paper on transparent TCP proxy in WCDMA and its on my site
    http://www.networkengineer.biz (I took a course in wireless
    architecture).


    On Thu, 21 Jul 2005, Darren Reed wrote:

    > In some mail from Fernando Gont, sie said:
    > >
    > > At 07:25 p.m. 20/07/2005, Darren Reed wrote:
    > >
    > > >In some mail from Fernando Gont, sie said:
    > > > > The IPv4 minimum MTU is 68, and not 576. If you blindly send packets
    > > > larger
    > > > > than 68 with the DF bit set, in the case there's an intermmediate with an
    > > > > MTU lower that 576, the connection will stall.
    > > >
    > > >And I think you can safely say that if you see any packets trying to
    > > >indicate that the MTU of a link is "68" then you should ignore it.

    > >
    > > Yes. But what about 296?
    > >

    > ...
    > > >I think it is reasonable to say anyone trying to advertise an MTU less
    > > >than 576 has nefarious purposes in mind.

    > >
    > > There are still some radio links with MTUs of 296 bytes.

    >
    > Go search with google....people still actively use smaller MTUs.
    >
    > What do you do? Where do you draw the line in the sand?
    >
    > Darren
    >


  6. #6
    Darren Reed
    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: (ICMP attacks against TCP) (was Re: HPSBUX01137 SSRT5954

    In some mail from Dana Hudes, sie said:
    >
    > you will find a range of MTU sizes in radio links of various sorts which
    > is not just 802.11 but also cellular including GPRS CDMA and WCDMA.
    > Now, in many instances there is a proxy between the mobile station and the
    > public network. In fact I wrote a powerpoint presentation summarizing such
    > a paper on transparent TCP proxy in WCDMA and its on my site
    > http://www.networkengineer.biz (I took a course in wireless
    > architecture).


    This website does nothing more than show ads if you are using mozilla.

    Please do better than that if you're posting to a public forum.

    In many instances, the traffic I've seen between base stations and
    mobile phones has a "normal" MTU. (I worked on software that handles
    wireless data.)

    Darren

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics