[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC3484 problem: scoping with site-locals/ULAs



On Tue, 9 May 2006, Walt Lazear wrote:
It sounds like the site in question has a single DNS and it's telling outsiders about private stuff that should not be allowed to escape.

Exactly the opposite. To solve this problem using split DNS, the DNS resolvers at the site would need to BLOCK any global IPv6 addresses from being received (in DNS packets) from _outside_ the site.

--
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings