Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP fragments and packet filters
From: Howard Barnett <HBarnett @ FastLane . NET>
Organization: Designs That Compute
Date: Mon, 04 Mar 1996 23:08:02 -0500
To: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Cc: Firewalls @ GreatCircle . COM
References: <Pine . BSF . 3 . 91 . 960301195334 . 3003C-100000 @ mcfeely . bsfs . org>

Rabid Wombat wrote:
> 
> On Fri, 1 Mar 1996, Paul Ferguson wrote:
> 
> > The fragmentation and, more importantly, reassembly should happen in this
> > case transparently long before it reaches your router/firewall/whatever.
> >
> > - paul
> 
> Yes - segment and re-assembly should occur at the edge devices.
> 
> >
> > At 10:28 PM 2/29/96 -0500, Charles B. Kaplan wrote:
> >
> > >>The only time you're ever likely to see a packet with FO=1 is if a bad guy is
> > >>knocking at your door.
> > >
> > >IE, my east coast LAN wants to connect to my west coast LAN, which will
> > >involve traversing (substitute your favorate backbone providers) ATM link.
> > >Therefor my 68byte header + data get dumped into larger (I forget frame size
> > >at the moment) ATM cell, which could POSSIBLY ?? cause one byte to cross a
> > >cell boundry, and thuse appear fragmented to the remote site ?
> > >
> ATM uses 53 byte cells, 48 bytes of payload, 5 bytes header. Much smaller
> than your IP packtes. SAR should occur before reaching your firewall,
> however.
> 
> - r.w.Right Lan Emulation makes the 48 byte payload transparent to IP.


References:
Indexed By Date Previous: Request for Information - Security
From: "S. W. Sidebottom" <72242 . 2264 @ compuserve . com>
Next: tcpdump
From: nicholscs @ agedwards . com (Nichols,Christopher)
Indexed By Thread Previous: Re: IP fragments and packet filters
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: Re: IP fragments and packet filters
From: Bill Conaway <Bill_Conaway @ iongate . staff . ichange . com>

Google
 
Search Internet Search www.greatcircle.com