[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: The IPv4 Internet MTU



On Fri, 12 Oct 2007, Iljitsch van Beijnum wrote:

There are basically two types of UDP protocols: the old / low volume ones such as the DNS, where a 512 / 576 limit is explicitly or implicitly understood,
And of course this assumption is no longer valid in the EDNS0 world where 
UDP packets can be as large as 6k.
Speaking of bad stateful firewalls, we've had enormous problems deploying 
EDNS0 in the wild due to firewalls that assume anything larger than 512 
can't possibly be a DNS packet, so they drop them. And lest you think this 
is low end stuff, Cisco's PIX was one of the most common AND worst 
offenders till they finally created an update for it. Now all we have to 
do is go around to every single site that's having problems with larger 
packets and convince them to upgrade.
and so it goes,

Doug

--

	If you're never wrong, you're not trying hard enough