Death of the Internet, Film at 11

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Wed Oct 26 05:30:02 UTC 2016


On Tue, 25 Oct 2016 18:54:22 -0500, Larry Sheldon said:

> What is it? 20 years? since the first time I was banned from NANOG for
> saying that the world would be a nicer place if EVERY true router
> refused to forward a packet whose SOURCE could not be reached from the
> port question.  (May not be stated clearly, but idea seems simple
> enough:  If the proposed ICMP message would not be routed to the port
> the packet came from, the best plan is probably to log the event and
> drop the ICMP and the rogue packet on the floor.)

That's not going to work when there's asymmetric routing. Say you get an
inbound packet from eth0 and the routing table says you should send it out on
eth2.  However, it has DF set and eth2 has a smaller MTU, so you need to send
back an ICMP FRAG reply.

Now, do you send it out, or do you create a PMTUD black hole by dropping the
reply because your local table says the source is routed out eth1?

Hint: there's a difference between strict uRPF and loose uRPF.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 484 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20161026/d6886494/attachment.sig>


More information about the NANOG mailing list