In the message <[EMAIL PROTECTED]>
dated Sat, Jan 06, 2007 at 09:10:26AM +1100,
Mark Andrews <[EMAIL PROTECTED]> writes:
>       It would be useful to have a additional column in the table
>       which specifies the maximum fragemented UDP response those
>       firewalls support.

It would also be useful to have an additional test case of the default
handling procedure (allowance/denial) of fragmented IPv4 packets for
each firewall product.  

On FreeBSD 4.11-RELEASE ipf, I had to write a rule set to explicitly
allow fragmented IPv4 packets; I suspect denying the fragmented packets
is the default setting for many firewall products.  

// Kenji Rikitake

_______________________________________________
DNSOP mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/dnsop

Reply via email to