3 ms·
If I understand correctly, the protocol stack is built on TCP, but they use different IP protocol numbers, so a router or firewall may easily pass TCP, but not
by rsaxvc 3y ago
If I understand correctly, the protocol stack is built on TCP, but they use different IP protocol numbers, so a router or firewall may easily pass TCP, but not MPTCP(either by configuration or age).
- jeroenhd 3y agoAs far as I understand, MPTCP works via a TCP option rather than a separate IP protocol number. To any normal firewall, the unknown option field shouldn't be cause for concern.
- rsaxvc 3y agoI had assumed that since IPPROTO_MPTCP(262)!=IPPROTO_TCP(6), they were using another protocol number for everything, but you're right that there's a TCP option involved too. But also, plenty of stateful firewalls will strip unknown options. Here's how to enable Ciscos to forward it: https://www.cisco.com/c/en/us/support/docs/ip/transmission-control-protocol-tcp/116519-technote-mptcp-00.html#anc8 https://www.cisco.com/c/en/us/support/docs/ip/transmission-c.... Edit: here's checkpoint: https://support.checkpoint.com/results/sk/sk114666 https://support.checkpoint.com/results/sk/sk114666
- jeroenhd 3y agoIPPROTO_MPTCP (262) is too big to fit into the byte that's reserved for the protocol number. I'm not sure what the reason is Linux has this protocol number, I'm guessing it's so that user mode sockets can easily request MPTCP sockets? I'm not too surprised about Cisco and Checkpoint. I suppose corporate networks are intentionally always a pain when it comes to new protocols and features.
- rsaxvc 3y agoI think you're right that it serves only as a way to communicate to the kernel that userspace wants MTCP socket.