> In short only the endpoint can determine the correct action to take
> when a bad-checksum-packet arrives....
>=20
> (maintaining a table of active connections through the router and
> recording the state of all those is unfeasable: we have a linux-route=
r
> here that has thousands of active connections going through it.)
>=20
We have the IP masquerading stuff which does exactly that.
In the general case, i.e. if you don't need to do masquerading, of cour=
se,
I agree with you -- the added overhead certainly isn't worth it.
--=20
Ambition: The glorious frailty of the noble mind.
-- Hoole
--=20
Matthias Urlichs \ XLink-POP N=FCrnberg | EMail: urlichs@smurf.=
noris.de
Schleiermacherstra=DFe 12 \ Unix+Linux+Mac | Phone: ...please use =
email.
90491 N=FCrnberg (Germany) \ Consulting+Networking+Programming+etc'i=
ng 42
PGP: 1B 89 E2 1C 43 EA 80 44 15 D2 29 CF C6 C7 E0 DE=20
Click <A HREF=3D"http://smurf.noris.de/~smurf/finger">here</A>.