White RoomNEW

Only The First Fragment

A stateless firewall is configured to permit UDP destination port 4789 and deny everything else. A 4000-byte VXLAN datagram arrives at a 1500-byte-MTU link and is fragmented into three IPv4 fragments.

What does the firewall see, and what does it have to decide?