Re: Firewall question

From: Chris (never@work)
Date: 03/15/03


From: "Chris" <never@work>
Date: Sat, 15 Mar 2003 20:10:22 -0000


"Lars M. Hansen" <badnews@hansenonline.net> wrote in message
news:bbm67v4d018iqai5ceia28e3iff4lh5spp@4ax.com...
> On Sat, 15 Mar 2003 11:27:55 -0500, PES spoketh
>
> >Me too, I find it hard to believe that a udp req could net a tcp reply.
> >Obviously the dns client don't know the size of the response in advance
and
> >would therefore issue the req as std udp.
> >
>
> From RFC 1035:
> "Messages carried by UDP are restricted to 512 bytes (not counting the
> IP or UDP headers). Longer messages are truncated and the TC bit is set
> in the header."
>
> I assume (never seen it happen) that if the TC bit is set, the client
> may re-issue the query over TCP, hence both the request and reply will
> be transmitted via TCP rather than UDP.
>
> Probably doesn't happen too often ...
>
> Lars M. Hansen
> http://www.hansenonline.net
> (replace 'badnews' with 'news' in e-mail address)

This had opened a can of worms hasn't it?? Anyway, you are quite correct
about the TCP thing. I've certainly learned something new today.

Cheers all.

Chris.



Relevant Pages

  • NFS problem with recent 2.6 kernels (also serial console weirdness)
    ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ... mounted filesystem with ordered data mode. ... Mounted root (ext3 filesystem) readonly. ...
    (Linux-Kernel)
  • Solaris 9 <---> linux (2.6.8) NFS file locking problem?
    ... to the same file placed on nfs filesystem. ... 100000 4 tcp 111 portmapper ... 100000 4 udp 111 portmapper ... 100021 1 udp 4045 nlockmgr ...
    (SunManagers)
  • Urgent help with Secure NFS.
    ... have that option - I'm just attempting to tunnel all NFS traffic to the ... 100000 4 tcp 111 rpcbind ... 100000 4 udp 111 rpcbind ... 100021 1 tcp 49153 nlockmgr ...
    (SSH)
  • Re: nfs error
    ... kernel: nfs: server ... So if your system uses ypbind be sure that is working properly before ... 100000 2 tcp 111 portmapper ... 100000 2 udp 111 portmapper ...
    (comp.sys.sun.admin)
  • Re: Incoherent E-mails
    ... The Novell crap was originally run on IPX ... The term in the early-mid nineties was "packet storm". ... The original advantage of UDP was ... > 60 bytes for TCP. ...
    (alt.computer.security)