Re: [c-nsp] TCP MSS CLAMPING issue
Gert Doering <[email protected]>
| Newsgroups | gmane.network.nsp.cisco |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Sun, Jan 23, 2022 at 05:10:42PM +0100, james list wrote:
> I suspect the current Cisco implementation does not change MSS because the
> syn-ack does not contain the MSS option.
If there is no MSS option, nothing can be adjusted - one would need extra
code to *add* such an option, which is more complex than "change one
number and adjust the checksum".
So, get your firewall vendor to fix their SYN-ACK-spoofing code.
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJh7YUDAAoJEB2Cnv7KVigSsUoL/3QeaD1MAzhguB8z4Gr2jyAa awv0qfrR7OEt9jhEWOhkcFq7jPC8nGL6b31bNZWnCobMj9uySEAuMXu9a7HSbH5G FIe921KU5sGbmSieVBFdbJvD8dVEP6b5fcaRJTYigXAHmE09aAW1MnMB6T2Gm4ic lADVq/GAVDZShkO/EAz2cWCzypjfAR1mVPoYdqQKmNVTjRzdEtyBEwA5/UWmXlvH bPS7k9+YpCmd5eFYntIXUdKmai5ilaXQR0yu4eNdG/M2zqrWhHyj1TwKZeVZ9i8U B4sJpsCe4KpwxtYrn3d9M6yuGkZQd3YwZWe0gjyI0rcrjEguHcVD2/9MD7+MR9Ae hulKMIxom7RrZqA1qiY8Hd8qGECU2jZwdO1ABSnK1c7NHtn/VAmKPTlj3lNDNCHu z6ci7gGBa2ioNKQoWDnk/1G/MhOkQEFJG1NKqx4888guH5SRb6dSqOQlp25djo7o RKEebsTkwqEsHXxyeEM+xruswBOP+iLfD6kFrk1lOg== =g4fl -----END PGP SIGNATURE-----