Quoth Nadav Har'El:

> Why not? If he didn't block ICMP Fragmentation Needed, TCP's automatic PMTU
> discovery would work and there would be no need in setting it manually,
> other than improvement of handshake time.

Not an issue, mostly. Block FR and DF and you have problems, but NOT
insane ones that the guy describes.

> And do all firewalls support fiddling with MSS values on SYNs passing
> through them? Ipchains couldn't do this (as far as I know). Can iptables?

iptables can.


-- 
---OFCNL
    This is MY list. This list belongs to ME! I will flame anyone I want.
Official Flamer/Cabal NON-Leader                              [EMAIL PROTECTED]

=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]

Reply via email to