Re: Problems with IP fragments (was: Problems with DNSSEC -- answer in fragmented UDP doesn't work)

2015-02-09 Thread Andre Albsmeier
On Wed, 28-Jan-2015 at 10:04:57 -0800, Freddie Cash wrote: > On Wed, Jan 28, 2015 at 9:53 AM, Lev Serebryakov wrote: > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA512 > > > > On 28.01.2015 20:38, Matthew Seaman wrote: > > > > > What do you get if you run the reply size test at DNS-OARC ?

Re: Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-31 Thread Kevin Oberman
On Fri, Jan 30, 2015 at 10:11 PM, David DeSimone wrote: > Kevin Oberman wrote: > > > > For ipfw you need something like "allow ip from any to me frag". If you > > want to restrict this to DNS, restrict it to dst-port 53. > > Unfortunately, UDP fragments only contain the port number in the very >

RE: Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-30 Thread David DeSimone
Kevin Oberman wrote: > > For ipfw you need something like "allow ip from any to me frag". If you > want to restrict this to DNS, restrict it to dst-port 53. Unfortunately, UDP fragments only contain the port number in the very first fragment. So you will not be able to forward the later fragment

Re: Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-30 Thread Ian Smith
On Fri, 30 Jan 2015 16:57:28 -0800, Kevin Oberman wrote: > On Wed, Jan 28, 2015 at 9:13 AM, Lev Serebryakov wrote: > > I could not resolve names with DNSSEC (for example, in freebsd.org > > domain) on two of my installations, one with FreeBSD 11 and other with > > FreeBSD 9.3. > > > > Sym

Re: Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-30 Thread Kevin Oberman
On Wed, Jan 28, 2015 at 9:13 AM, Lev Serebryakov wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > > I could not resolve names with DNSSEC (for example, in freebsd.org > domain) on two of my installations, one with FreeBSD 11 and other with > FreeBSD 9.3. > > Symptoms are the same:

Re: Problems with IP fragments (was: Problems with DNSSEC -- answer in fragmented UDP doesn't work)

2015-01-28 Thread Freddie Cash
On Wed, Jan 28, 2015 at 9:53 AM, Lev Serebryakov wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On 28.01.2015 20:38, Matthew Seaman wrote: > > > What do you get if you run the reply size test at DNS-OARC ? > > > > https://www.dns-oarc.net/oarc/services/replysizetest > 0 lines (em

Problems with IP fragments (was: Problems with DNSSEC -- answer in fragmented UDP doesn't work)

2015-01-28 Thread Lev Serebryakov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 28.01.2015 20:38, Matthew Seaman wrote: > What do you get if you run the reply size test at DNS-OARC ? > > https://www.dns-oarc.net/oarc/services/replysizetest 0 lines (empty answer) at CURRENT, only "rst.x1013.rs.dns-oarc.net." on 9.3. Looks

Re: Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-28 Thread Matthew Seaman
On 01/28/15 17:13, Lev Serebryakov wrote: > > I could not resolve names with DNSSEC (for example, in freebsd.org > domain) on two of my installations, one with FreeBSD 11 and other with > FreeBSD 9.3. > > Symptoms are the same: answer is sent as fragmented IP/UDP packet and > second part of ans

Problems with DNSSEC -- answer in fragmented UDP doesn't work

2015-01-28 Thread Lev Serebryakov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I could not resolve names with DNSSEC (for example, in freebsd.org domain) on two of my installations, one with FreeBSD 11 and other with FreeBSD 9.3. Symptoms are the same: answer is sent as fragmented IP/UDP packet and second part of answer is