[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: filtering packets with unknown options
On Jul 12, 2006, at 11:33 AM, Iljitsch van Beijnum wrote:
There is of course the tiny detail of how to implement this.
Firewalls do a lot of processing so it's not completely outside the
realm of possibility to assume that they could remove extension
headers, but routers certainly aren't going to do this.
There are router implementations that implement a variety of
firewall. I don't see any reason they couldn't, apart from the DOS
implications (which firewalls have as well).