Re: [Hampshire] Are UDP responses allowed from a different s…

Top Page
Author: Hugo Mills
Date:  
To: lug, Hampshire LUG Discussion List
Subject: Re: [Hampshire] Are UDP responses allowed from a different sourceport?

Reply to this message
gpg: failed to create temporary file '/var/lib/lurker/.#lk0x57c17100.hantslug.org.uk.26701': Permission denied
gpg: keyblock resource '/var/lib/lurker/pubring.gpg': Permission denied
gpg: Signature made Sat Nov 7 18:57:06 2009 GMT
gpg: using DSA key 20ACB3BE515C238D
gpg: Can't check signature: No public key
On Sat, Nov 07, 2009 at 11:45:43AM -0000, Vic wrote:
>
> >    I believe that the filtering is incorrect, and that the machine
> > returning its packet from a high port is correct, if unusual. I'm not
> > entirely sure *why* I believe that, though.

>
> I'm with Hugo - except I do know why I believe that.
>
> UDP is a connectionless protocol; all that matters is what's in the
> payload. Previous packets in the datastream are irrelevant to the delivery
> of this one.
>
> So the fact that it's coming from a different source port to the one that
> the previous packet went to doesn't matter; it's still a UDP packet, and
> that doesn't depend on any connection state.


I could have made the same argument -- however, that's still not
authoritative (it's merely highly plausible). What I was trying to say
was that I couldn't point to the line of the RFC that states that it's
OK(*). :)

Hugo.

(*) And unlike Ibid, below, I don't know everything. Yet.

--
=== Hugo Mills: hugo@... carfax.org.uk | darksatanic.net | lug.org.uk ===
PGP key: 515C238D from wwwkeys.eu.pgp.net or http://www.carfax.org.uk
--- The trouble with you, Ibid, is you think you know everything. ---