Re: UDP error handling

From: Barry Margolin (barmar_at_alum.mit.edu)
Date: 04/04/05


Date: Mon, 04 Apr 2005 15:42:36 -0400

In article <d2s25t$913$1@nntp.webmaster.com>,
 "David Schwartz" <davids@webmaster.com> wrote:

> "Barry Margolin" <barmar@alum.mit.edu> wrote in message
> news:barmar-DD25E1.04132202042005@comcast.dca.giganews.com...
>
> >> Who said he wasn't using port 53?
>
> > No one. But that would be ridiculous, so I'll give him the benefit of
> > the doubt.
>
> Actually, that's not ridiculous. A lot of of firewalls block unknown UDP
> so sometimes people look for ports that the firewalls pass and use them.
>
> >> And there are many documented cases of
> >> proxies munging data they thought that they understood.
> >
> > URLs, please?
>
> Are you saying you have never heard of a case where a NAT box 'repaired'
> the checksum of a UDP packet that was received corrupt because it didn't
> check the checksum before rewriting the destination address?

No, I've never heard of a proxy modifying the payload when it doesn't
know the application protocol.

> It's hard to find URLs on the Internet because it's not clear what terms
> to search for. But I have personally dealt with many cases where proxies,
> firewalls, and LSPs thought they understood the data I was sending and made
> manipulations that might be sensible for other protocols but made no sense
> for an arbitrary protocol layered over TCP or UDP.
>
> http://forums.bitpass.com/viewtopic.php?p=136
> http://www.livejournal.com/community/lj_dev/666626.html
> http://www.uwsg.iu.edu/hypermail/linux/net/9609.3/0024.html

None of these seem to be examples of what you're describing. I have no
trouble believing the case where a NAT box doesn't verify the checksum
of a received packet before doing the header rewrite.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***


Relevant Pages

  • Hits just keep on coming! What does it mean?
    ... I'm new to firewalls (just hooked up to cable and figured I should set one ... well but I get these constant hits as follows: ... protocol: udp, service: ipp ...
    (comp.os.linux.security)
  • Hits just keep on coming.....
    ... I'm new to firewalls (just hooked up to cable and figured I should set one ... but I get these constant hits as follows: ... protocol: udp, service: ipp ...
    (comp.security.firewalls)
  • Re: Hardware firewall blocking L2TP/IPSec VPN
    ... Protocol Info ... Frame 162 ... [Coloring Rule Name: UDP] ... Next payload: Security Association ...
    (microsoft.public.isa.vpn)
  • Re: Allow Wimba Live Classroom via ISA 2004 on SBS 2003
    ... Maybe I can get it to work by defining the custom protocol with primary UDP ... If not a custom access rule, to what rule do I attach the custom protocol? ... Port Range From: 5998 To: 5998. ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] Allowing DNS servers to operate behind NetScreen 500
    ... The reason for my response was that I don't know of any ... >> currently relevant reason for DNS responses to be over 512 bytes in size. ... There's L4 modes that most firewalls have -- they ... just dumb down the firewall's L7 handling of the protocol in question -- ...
    (Firewall-Wizards)