Received: with ECARTIS (v1.0.0; list netdev); Thu, 19 May 2005 05:49:26 -0700 (PDT) Received: from arnor.apana.org.au (arnor.apana.org.au [203.14.152.115]) by oss.sgi.com (8.12.10/8.12.10/SuSE Linux 0.7) with ESMTP id j4JCnHF3009500 for ; Thu, 19 May 2005 05:49:18 -0700 Received: from gondolin.me.apana.org.au ([192.168.0.6] ident=mail) by arnor.apana.org.au with esmtp (Exim 3.35 #1 (Debian)) id 1DYkRs-0003UH-00; Thu, 19 May 2005 22:48:24 +1000 Received: from herbert by gondolin.me.apana.org.au with local (Exim 3.36 #1 (Debian)) id 1DYkRp-0007oh-00; Thu, 19 May 2005 22:48:21 +1000 Date: Thu, 19 May 2005 22:48:21 +1000 To: Thomas Graf Cc: Rick Jones , netdev@oss.sgi.com Subject: Re: [RFC/PATCH] "strict" ipv4 reassembly Message-ID: <20050519124821.GA686@gondor.apana.org.au> References: <428B6B72.5010407@hp.com> <20050519122319.GH15391@postel.suug.ch> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20050519122319.GH15391@postel.suug.ch> User-Agent: Mutt/1.5.6+20040907i From: Herbert Xu X-archive-position: 1354 X-ecartis-version: Ecartis v1.0.0 Sender: netdev-bounce@oss.sgi.com Errors-to: netdev-bounce@oss.sgi.com X-original-sender: herbert@gondor.apana.org.au Precedence: bulk X-list: netdev Content-Length: 949 Lines: 21 On Thu, May 19, 2005 at 02:23:19PM +0200, Thomas Graf wrote: > > I agree, however defining a value of 600 system wide is horrible for > all hosts that behave "correctly". So what we could do is take probes > of the id distribution and define the threshold on a per peer scope. > > Example: Once in a while we start a probe and set a bit in a bitmap > for every id that matches a defined window. Not sure about the size of > that bitmap yet but 2048 bits might be a good start. The first fragment Sorry, but this scheme is way too complex for a problem that only affects a tiny section of the community. If you really want to do this then do it as a static route flag instead of something that the system tries to auto-detect. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt