[dns-operations] DNS Attack over UDP fragmentation

Stephane Bortzmeyer bortzmeyer at nic.fr
Wed Sep 4 14:30:18 UTC 2013


On Wed, Sep 04, 2013 at 11:01:43PM +0900,
 Yasuhiro Orange Morishita / 森下泰宏 <yasuhiro at jprs.co.jp> wrote 
 a message of 40 lines which said:

> RELNOTES of NSD 3.2.9 describes the following,
> we may separate max-udp-size value for IPv4 and for IPv6.

This controls the size of the IP datagrame sent by the application
(the name server). It does not control the path MTU seen by the Unix
kernel, which will be the deciding factor triggering (or not)
fragmentation.
 



More information about the dns-operations mailing list