|
Firewalls (December 1995) |
screend doesn't do any reassembly. It does have a fragment cache so that it can drop or pass fragment trailers if it dropped or passed the fragment leader. This keeps you from wasting bandwidth with fragements that wont reassemble and the associated icmp errors and the end system resources and closes a possible communications channel of just passing fragment tailers but it doesn't really help in the fragment filtering problem. geoff
|