[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IETF IPv6 platform configuration



On 12-jun-2006, at 23:03, Pekka Savola wrote:

Is there a compelling reason to filter ICMP at all?

IMHO, this is a valid question.

Don't bother thinking about an answer, people are going to do it anyway.

An important problem with all kinds of filtering in IPv6 is that most filters don't support the "protocol chain" concept so if you have a fragment header or an AH header or some such between the IPv6 header and the payload protocol, you're out of luck and the payload protocol isn't recognized.

There also happens to be a document, draft-ietf-v6ops-icmpv6- filtering-recs-00.txt that discusses this very issue. It might be interesting to have folks read that and provide feedback to v6ops list (v6ops@ops.ietf.org) if they think there's something amiss with it.

Please use "hop limit" rather than "hop count" as the former is the official name of the field.

And do we really need 34 pages just to say "if you're so paranoid that you want to filter ICMPv6, at least have the sense to let these ones through"?

We live in an age of information overload, conciseness is a virtue!