Great Circle Associates Firewalls
(May 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: New file transfer protocol: FSP
From: avalon @ coombs . anu . edu . au (Darren Reed)
Date: Sat, 8 May 93 4:05:25 EST
To: chk @ alias . com (C. Harald Koch)
Cc: brent @ GreatCircle . COM, firewalls @ GreatCircle . COM
In-reply-to: <9305071448 . AA07727 @ dino . alias . com>; from "C. Harald Koch" at May 7, 93 11:48 am
Reply-to: avalon @ coombs . anu . edu . au

In some email I received from C. Harald Koch, Sie wrote:
[...]
>    systems that have been placed into TCP over the years. FTP is just fine
>    on modern IP systems, since network transients don't tear down a TCP
>    connection anymore (That was a BSD bug, and has slowly been eradicated).

Ahem.  Of all the Unixes I know, NetBSD has it fixed.  Everything based on
4.3BSD is flawed (there being a patch for SunOS to help) and this includes
a very large range of Unix variants.  Also there is a bug in NET-2 (fixed
for NetBSD).

> Apparently, FSP has started causing problems already on some slower IP
> links, since it doesn't do any congestion control. It's only a matter of
> time before the larger network providers notice it, and take steps.
> 
> >From a security point of view, it's like any other UDP service, i.e.
> impossible to control. :-)

But also impossible to monitor...how can a network provider determine
what portion of traffic is being used for FSP if there is no fixed port
number ?  And then, what effective action can they take ?  If you run
FSP on a NFSless machine you can use port 2049, what now ?

Darren



References:
Indexed By Date Previous: Re: New file transfer protocol: FSP
From: chk @ alias . com (C. Harald Koch)
Next: Re: New file transfer protocol: FSP
From: Brent Chapman <brent @ GreatCircle . COM>
Indexed By Thread Previous: Re: New file transfer protocol: FSP
From: chk @ alias . com (C. Harald Koch)
Next: Re: New file transfer protocol: FSP
From: Brent Chapman <brent @ GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com