[ipv6hackers] thc-ipv6 v3.0, IPv6 complexity and evasions

Jeremy Stanley fungi at yuggoth.org
Sat Oct 17 19:06:19 CEST 2015


On 2015-10-17 17:26:39 +0200 (+0200), Marc Heuse wrote:
[...]
> and please do not make a joke about oversized UDP packets. with
> DNSSEC this is actually required. and we need DNSSEC. we don't see
> that problem much because companies don't implement it (yet).
[...]

I'm reminded of ECN black holes because of networks blocking
unexpected diffserv options, PMTUd black holes because of networks
blocking all ICMP (including NTF), broken IPSec because of networks
blocking "unusual" IP protocols... the list goes on. In my years as
a network engineer, the story I always got from the offending
network operators was "you're the only one complaining to us about
this so clearly it's not a major problem."
-- 
Jeremy Stanley


More information about the Ipv6hackers mailing list