[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: ingress filteing problem
I'm probably late to the party, but don't (1) and (2) break
So IPsec transport mode would be a non-goal?
From: "Kanchei Loa" <email@example.com>
> The following are solutions that won't break non-multi6 TCP and UDP
> one end of the communication implements multi6):
> (1) Match the source address to ISP.
> (2) Fake the source address to ISP.
> Before we talk about pros, cons and other issues, It is beneficial
> have a complete list of possible solutions for ISP ingress filtering
> won't break non-multi6 TCP and UDP (only one end of the
> implements multi6). My opinion is that any multi6 solution that
> existing non-multi6 TCP and UDP at another end of the connection
> deployment difficulty.
> Am I missing something?