Re: [fw-wiz] Transparent proxies and PMTUD on the (WWW) server side

From: Carson Gaspar (carson_at_taltos.org)
Date: 08/21/03

  • Next message: Nimesh Vakharia: "[fw-wiz] Firewall Statefullness:"
    To: firewall-wizards@honor.icsalabs.com
    Date: Thu, 21 Aug 2003 16:52:51 -0400
    
    

    If an ALG supports transparent proxying, enables PMTUD, and does not
    intercept ICMP must fragment, the ALG is broken. File a high priority
    trouble ticket with your vendor.

    In the mean time, the _only_ sane thing to do is disable PMTUD, if you have
    that much access to the underlying OS.

    -- 
    Carson
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Nimesh Vakharia: "[fw-wiz] Firewall Statefullness:"