ICMPv6 PTBs and IPv6 frag filtering (particularly at BGP peers)

Saku Ytti saku at ytti.fi
Thu Jan 12 19:31:53 UTC 2017


On 12 January 2017 at 17:02, Fernando Gont <fgont at si6networks.com> wrote:
> That's the point: If you don't allow fragments, but your peer honors
> ICMPv6 PTB<1280, then dropping fragments creates the attack vector.

Thanks. I think I got it now. Best I can offer is that B could try to
verify the embedded original packet? Hopefully attacker won't have
access to that information. An if attacker has access to that
information, they may as well do TCP RST, right?

Didn't we have same issues in IPv4 with ICMP unreachable and frag
neeeded, DF set? And vendors implemented more verification if the ICMP
message should be accepted.

-- 
  ++ytti



More information about the NANOG mailing list