[ipv6hackers] Operational ICMPv6 Filtering

Simon Perreault simon.perreault at viagenie.ca
Thu May 31 15:42:01 CEST 2012


On 2012-05-31 09:30, daniel.bartram at bt.com wrote:
> Thanks Simon. This particular ACL was for a WAN facing link towards
> an ISP infrastructure where a static /127 is used. I wasn't sure, but
> I didn't think blocking type 4 would have any affect at all?

I wouldn't ignore an RFC recommendation without being sure...

The nice thing is that there's an RFC you can point to when people 
question why such and such ICMP types/codes are open. Following best 
current practices is what I would expect of a good network engineer.

Simon
-- 
DTN made easy, lean, and smart --> http://postellation.viagenie.ca
NAT64/DNS64 open-source        --> http://ecdysis.viagenie.ca
STUN/TURN server               --> http://numb.viagenie.ca



More information about the Ipv6hackers mailing list