[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Ipsec] big IKE packets



> 
> Can't modern firewalls tag the initial segment's ID, and let 
> matching IDs
> through?  I know there's packet reordering and 
> implementations that send the
> last fragment first, but the former is relatively rare, and 
> the latter can be fixed.

Keep in mind that Linux implemenations send out the last
fragment first, so you're going to see a lot of that.  We're
not going to hold our breath waiting for that to be changed!

Bob

_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec