[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

pf and pmtu discovery



Hi,

with scrub in all set at the firewall, will openbsd handle icmp packets 
of type unreach code needfrag automatically, because of the statefulness?
as far as i know, icmp packtes like port/host/network unreachable are 
allowed by the keep state statements, does this also apply for the need 
fragment codes of icmp unreachable messages?

or shall I have to add a rule to allow these packets explicitly?

thanks 
lars

-- 
GMX Produkte empfehlen und ganz einfach Geld verdienen!
Satte Provisionen f|r GMX Partner: http://www.gmx.net/de/go/partner



Visit your host, monkey.org