[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Ipsec] big IKE packets
>
> Can't modern firewalls tag the initial segment's ID, and let
> matching IDs
> through? I know there's packet reordering and
> implementations that send the
> last fragment first, but the former is relatively rare, and
> the latter can be fixed.
Keep in mind that Linux implemenations send out the last
fragment first, so you're going to see a lot of that. We're
not going to hold our breath waiting for that to be changed!
Bob
_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec