Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Windows NT & Firewalls
From: Russ <Russ . Cooper @ RC . Toronto . on . ca>
Date: Tue, 16 Jul 1996 15:54:12 -0400
To: "'Ken Hardy'" <ken @ bridge . com>, "'gdo @ shellus . com'" <gdo @ shellus . com>
Cc: "'Firewalls'" <firewalls @ GreatCircle . COM>

Ken said...
"Russ Cooper (I think) sent me some configuration suggestions to try on
the NT system to see if it could be make to behave properly in this
>scenario, but I've never had a chance to try them and see if it helps.  I'm
>sure I have his message around here somewhere, but I cannot find it right
now. If he sees this, perhaps he'll repeat it to the list."

>Try changing the following entry in your registry and see if this changes
>NT's behaviour with respect to your proxy. I suspect it will.
>
>Cheers,
>Russ
>
>
>HKEY_LOCAL_MACHINE
>  \SYSTEM
>    \CurrentControlSet
>      \Services
>        \Tcpip
>          \Parameters
>
>Value: EnablePMTUBHDetect	REG_DWORD
>Range: 0 or 1
>Default: 0 (false)
>
>Setting this parameter to 1 (True) causes TCP to try and detect "Black Hole"
>routers while doing Path MTU Discovery. A "Black Hole" router does not return
>ICMP Destination Unreachable messages when it needs to fragment a TCP packet
>with the Don't Fragment bit set. TCP depends on receiving these messages to
>perform Path MTU Discovery. With this feature enabled, TCP will try to send
>segments without the Don't Fragment bit set if several retransmissions of a
>segment go unacknowledged. If the segment is acknowledged as a result, the
>MSS will be decreased and the Don't Fragment bit will be set in future
>packets on the connection. Enabling black hole detection increases the
>maximum number of retransmissions performed for a given segment.
>
>Cheers,
>Russ
>...running MS Exchange Server 4.0 on NT 4.0, the future is here now.
>

Indexed By Date Previous: Re: Windows NT & Firewalls
From: Ken Hardy <ken @ bridge . com>
Next: Re: CERT Advisories (was: Re: Dirty dogs)
From: ygerman <ygerman @ genre . com>
Indexed By Thread Previous: RE: Windows NT & Firewalls
From: Russ <Russ . Cooper @ RC . Toronto . on . ca>
Next: 'ntsecurity' list ref
From: "Norton, Dave" <dnorton @ trane . com>

Google
 
Search Internet Search www.greatcircle.com