Re: ECN, DNS and Firewalls

2018-12-27 Thread Mark Andrews
> On 28 Dec 2018, at 2:49 pm, valdis.kletni...@vt.edu wrote: > > On Fri, 28 Dec 2018 13:35:04 +1100, Mark Andrews said: >> There are major operators that still have STUPID firewall settings >> in front of DNS servers that drop SYN packets with ECE and CWR set >> 17 years after ECN was specified

Re: ECN, DNS and Firewalls

2018-12-27 Thread valdis . kletnieks
On Fri, 28 Dec 2018 13:35:04 +1100, Mark Andrews said: > There are major operators that still have STUPID firewall settings > in front of DNS servers that drop SYN packets with ECE and CWR set > 17 years after ECN was specified. Time to name-n-shame?

ECN, DNS and Firewalls

2018-12-27 Thread Mark Andrews
There are major operators that still have STUPID firewall settings in front of DNS servers that drop SYN packets with ECE and CWR set 17 years after ECN was specified. Do you really want to add a second to EVERY DNS lookup that needs to use TCP? Modern OS actually attempt to use ECN by default.