Re: ECN & cisco firewall

From: Andi Kleen (ak@suse.de)
Date: Sat Sep 09 2000 - 09:14:15 EST


On Sat, Sep 09, 2000 at 03:38:26AM -0700, David S. Miller wrote:
> Date: Sat, 9 Sep 2000 12:32:34 +0200
> From: Jamie Lokier <lk@tantalophile.demon.co.uk>
>
> So our TCP stack can observe this and say "ah, that route doesn't
> do ECN; let's retry without ECN and see if we get a better
> response".
>
> This might work. Although, a tougher case to handle are the
> firewalls which just silently drop the packet if ECN bits are
> set. The timeout is just too long to make a "backdown and try
> withough ECN" scheme worthwhile in that case.

It is just the same thing as pmtu blackhole detection, and very
hard to get right. I tried to implement a good scheme for pmtu blackhole
detection for linux, but failed.

-Andi
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Fri Sep 15 2000 - 21:00:12 EST