Brian E Carpenter <[email protected]> writes:

> "By in large, this flow label changing behaviour has been traced to
> IPv6 supporting CPE/firewalls, which change the flow label between the
> initial syn and the ack."
> 
> Broken middleboxes can prevent anything from working properly.

With my <operator> hat on, we have indeed run into a problem where a
small (~ 2%) of IPv6 TCP sessions to us were failing due to FlowLabels
being used in ECMP hashing.  We had to turn off the usage of FlowLabel
in the hashing because of even a small real world impact to end-users.
-- 
Wes Hardaker
USC/ISI

_______________________________________________
OPSEC mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/opsec

Reply via email to