Re: [nottingham] ECN and the wonderful world of firewalls

From: Robert Davies (Rob_Davies@NTLWorld.Com)
Date: Sat 05 May 2001 - 23:40:22 BST


Came across a real nasty one a few years back, when MTU discovery came in,
as some routers would simply drop packets with the don't fragment bit set,
rather than return the right ICMP.
The effect was most connections would seem to work, but large ftp jobs would
hang very rapidly.

The ECN option is turned off in Suse7.1, with 2.4 kernel. If you use a
proxy server, or masquerade then obviously you should only need to worry on
your gateway host.

This sort of thing come with the turf of living on the bleeding edge of
networking, it usually takes at least 6 months before all the routers get
upgraded.

Rob

--------------------------------------------------------------------
http://www.lug.org.uk http://www.linuxportal.co.uk
http://www.linuxjob.co.uk http://www.linuxshop.co.uk
--------------------------------------------------------------------



This archive was generated by hypermail 2.1.3 : Thu 22 Nov 2001 - 13:11:56 GMT