Subject: Re: DF strikes again
To: Rob Quinn <rquinn@sprint.net>
From: David Brownlee <abs@NetBSD.ORG>
List: current-users
Date: 03/15/2001 19:25:27
	Could I persuade anyone to send in an entry for the NetBSD
	networking FAQ covering this (including reference to the below
	URL might not be a bad idea :)

		David/absolute -- www.netbsd.org: No hype required --


On Thu, 15 Mar 2001, Rob Quinn wrote:

> > "firewalls MUST NOT block packets that the legitimate use of the Internet
> > rely on for proper operation" or something like that.
>
>  Probably 10% of the complaints to our security mailbox are from people hyper-
> ventilating over our backbone routers "hacking their computer" with ICMP
> packets.
>
> > So, the trick is to find the RFC #, and contact the owner of the firewall and
> > scream that they are "not RFC-mumble compliant!!!"  :-)
>
>  Good luck. I often refer admins to http://www.worldgate.com/~marcs/mtu/.
>