Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 2 Dec 1998 14:04:20 -0700
From:      Nate Williams <nate@mt.sri.com>
To:        Guido van Rooij <guido@gvr.org>
Cc:        Nate Williams <nate@mt.sri.com>, Daniel Eischen <eischen@vigrid.com>, dillon@apollo.backplane.com, hackers@FreeBSD.ORG, luigi@labinfo.iet.unipi.it
Subject:   Re: TCP bug
Message-ID:  <199812022104.OAA07720@mt.sri.com>
In-Reply-To: <19981202215730.B23018@gvr.org>
References:  <199812021626.LAA27156@pcnet1.pcnet.com> <199812021636.JAA06068@mt.sri.com> <19981202215730.B23018@gvr.org>

next in thread | previous in thread | raw e-mail | index | archive | help
> In my previous mail I already stated why things can go wrong if the
> www server on the internet has a badly configured packet filter.
> In your case it seems that your router is badly configured. Does it
> filter out ICMP ICMP_UNREACH_NEEDFRAG pakcets from the ethernet to
> the ouside, but not from your router to the outside?

See my followup.  I don't filter out ICMP type 3 packets, but instead
allow them.  (I can't take any credit for this, it was part of the
firewall ruleset PHK gave me years ago...)


Nate

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199812022104.OAA07720>