Great Circle Associates Firewalls
(June 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP packet filtering...the non-obvious fix
From: Scott Barman <scott @ Disclosure . COM>
Date: Tue, 6 Jun 1995 16:29:49 -0400 (EDT)
To: Paul Traina <pst @ Shockwave . COM>
Cc: firewalls @ greatcircle . com, cgr @ livingston . com
In-reply-to: <199506022221 . PAA01047 @ precipice . shockwave . com>

On Fri, 2 Jun 1995, Paul Traina wrote:

<snip>
> RFC791 demands that an IP stack must be capable of passing an 8 byte IP data
> payload without further fragmentation (fragments sit on 8 byte boundaries).
> Since an IP header can be up to 60 bytes long (including options), this means
> that the minimum MTU on a link should be 68 bytes.
> 
> A typical IP header is only 20 bytes long and can therefore carry 48 bytes of
> data.  No one in the real world should EVER be generating a TCP packet with
> FO=1, as it would require both that a previous system fragmenting IP data down
> to the 8 byte minimum and a 60 byte IP header.
> 
> The only time you're ever likely to see a packet with FO=1 is if a bad guy is
> knocking at your door.

Then would it not be wise to punt the packets whose FO does not land
on an 8-bit boundry?  Or did I miss something... (which would be par
for the course :-)?

scott barman
--
scott barman                  DISCLAIMER: I speak to anyone who will listen,
scott @
 disclosure .
 com                      and I speak only for myself.
barman @
 ix .
 netcom .
 com
  "Micro$oft and Windoze/NT will be the cause of the de-evolution of
   netowrk security just as the original PC and BASIC was the cause of
   the de-evolution of programming."



References:
Indexed By Date Previous: Re: Vendor Lines
From: Michael Richardson <mcr @ milkyway . com>
Next: Re: Vote on newsgroup
From: Jeff Murphy <jcmurphy @ smurfland . cit . buffalo . edu>
Indexed By Thread Previous: Re: IP packet filtering...the non-obvious fix
From: pst @ cisco . com (Paul Traina)
Next: Re: IP packet filtering...the non-obvious fix
From: wbunting @ inri . com (Bill Bunting)

Google
 
Search Internet Search www.greatcircle.com