Over-Zealous Security Administrators Are Breaking the Internet
暂无分享,去创建一个
As the security threats on the Internet are becoming more prevalent, firewalls and other forms of protection are becoming more commonplace. Unfortunately, improperly configured firewalls can cause a variety of problems. One particularly nasty problem is when a firewall administrator chooses to use - or continue using - Path MTU Discovery (a good choice in most situations), but blocks packets required for the protocol to work: ICMP type 3 code 4 packets. This problem, the Path MTU Discovery Black Hole, has been discussed many times before. However with under- 1500 MTU protocols such as PPPoE becoming common for both home and business high-speed connections, this problem is affecting more people than ever before.
[1] Stephen E. Deering,et al. Path MTU Discovery for IP version 6 , 1996, RFC.
[2] Kevin Lahey,et al. TCP Problems with Path MTU Discovery , 2000, RFC.
[3] David Skoll. A PPPoE Implementation for Linux , 2000, Annual Linux Showcase & Conference.