Joe Touch wrote: > I repeat: nodes that encap or decap are acting as sources or sinks, not > relays. I'm afraid firewalls are relays. > Nodes such as NATs and firewalls act as end hosts on the public side and > routers on the private side. Which is why they need to obey RFC1122 > semantics on the public side. So, you think firewalls should reassemble fragments. Wow! Masataka Ohta