Hi Alaerte,

The attack is intended to force PMTUD to lower the outgoing packet size. 
  This increases fragmentation of outgoing packets and thus load on the 
processor.  Cisco IOS was modified to mitigate against, but not prevent, 
such attacks.  I think the change was just to delay the response to such 
packets.  Forget in which versions this was first implemented in but 
think it was about 18 months ago.

Paul.

[EMAIL PROTECTED] wrote:
>  
> Hi,
> 
> Have you heard about attacks trying to explore generation of packet too
> big ICMP messages?
> 
> Tks,
> Alaerte
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
> 


-- 
HEAnet Limited
Ireland's Education & Research Network
5 George's Dock, IFSC, Dublin 1, Ireland
Tel:  +353.1.6609040
Web:  http://www.heanet.ie
Company registered in Ireland: 275301

Please consider the environment before printing this e-mail.
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to