Quoth Nadav Har'El:
> Why not? If he didn't block ICMP Fragmentation Needed, TCP's automatic PMTU
> discovery would work and there would be no need in setting it manually,
> other than improvement of handshake time.
Not an issue, mostly. Block FR and DF and you have problems, but NOT
insane ones that the guy describes.
> And do all firewalls support fiddling with MSS values on SYNs passing
> through them? Ipchains couldn't do this (as far as I know). Can iptables?
iptables can.
--
---OFCNL
This is MY list. This list belongs to ME! I will flame anyone I want.
Official Flamer/Cabal NON-Leader [EMAIL PROTECTED]
=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]