Subject: Re: DF strikes again
To: Rob Quinn <rquinn@sprint.net>
From: David Brownlee <abs@NetBSD.ORG>
List: current-users
Date: 03/15/2001 19:25:27
Could I persuade anyone to send in an entry for the NetBSD
networking FAQ covering this (including reference to the below
URL might not be a bad idea :)
David/absolute -- www.netbsd.org: No hype required --
On Thu, 15 Mar 2001, Rob Quinn wrote:
> > "firewalls MUST NOT block packets that the legitimate use of the Internet
> > rely on for proper operation" or something like that.
>
> Probably 10% of the complaints to our security mailbox are from people hyper-
> ventilating over our backbone routers "hacking their computer" with ICMP
> packets.
>
> > So, the trick is to find the RFC #, and contact the owner of the firewall and
> > scream that they are "not RFC-mumble compliant!!!" :-)
>
> Good luck. I often refer admins to http://www.worldgate.com/~marcs/mtu/.
>