by Craig Miller
Overcoming fragmentation |
Filtering all Fragmentation Headers can lead to DNS failures
Case in point, Google's public IPv6 DNS servers until recently (Oct 2017) were clearly filtering fragmented responses (from authoritative servers). Small requests would succeed while large requests would fail.Careful with that Axe Eugene
While is is a good idea to filter extension headers, such as the fragmentation header when the packet is on link (Advice for IPv6 Router Advertisement Guard RFC 7113). One should not apply a blanket filter to all fragmented packets. Although PMTUD (Path MTU Discovery) is quite good at reducing fragmentation, there are valid reasons why a packet, such as a DNS response with many IPv6 addresses, could be fragmented.
Be careful with filters/ACLs/Firewall Rules, and be sure you are only filtering unwanted traffic.
* creative commons photo by James Ho
This comment has been removed by a blog administrator.
ReplyDelete