[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Comments on draft-wbeebee-ipv6-cpe-router-01.txt



Hemant,

> Ole said: why do you need a global address on the WAN interface because
> the CPE router is a router??
>
> RPF (Reverse Path Forwarding) will fail and if RPF fails for a router,
> due to security concerns, the router should drop the incoming packet. If
> the WAN interface of the CPE Router does not have a global IPV6 address,
> how is RPF going to work? RPF needs global IPv6 addresses.

that is incorrect. you do not need a global address to verify the SA.
we could go into details on "RPF checking", but before that, why do
you even want RPF checking on a CPE router, that belongs on the
provider edge.

> We haven't looked at the problem with a fine tooth and comb but when we
> do we will list all cases for what IPv6 routing and data forwarding
> breaks down if a routed interface of a router has only a link-local
> address.

as I have said multiple times before I am not aware of any, nor have I
seen anyone else cite any examples.

/ot