[dns-operations] L-Root Maintenance 2010-01-27 1800 UTC - 2000 UTC
Florian Weimer
fw at deneb.enyo.de
Wed Feb 3 14:04:05 UTC 2010
* Phil Regnauld:
> How likely is it that this will break completely with today's
> existing stateful inspection packet filters ?
The 2002 date I remembered was when I helped to bury SYN(+FIN)+data
for security reasons. The issue is not so much stateful filters, but
stateless ones. I suspect that many sites block funny flag
combinations because it's active by default if you do any form of TCP
normalization.
More information about the dns-operations
mailing list