[ipv6hackers] Operational ICMPv6 Filtering
Simon Perreault
simon.perreault at viagenie.ca
Thu May 31 15:42:01 CEST 2012
On 2012-05-31 09:30, daniel.bartram at bt.com wrote:
> Thanks Simon. This particular ACL was for a WAN facing link towards
> an ISP infrastructure where a static /127 is used. I wasn't sure, but
> I didn't think blocking type 4 would have any affect at all?
I wouldn't ignore an RFC recommendation without being sure...
The nice thing is that there's an RFC you can point to when people
question why such and such ICMP types/codes are open. Following best
current practices is what I would expect of a good network engineer.
Simon
--
DTN made easy, lean, and smart --> http://postellation.viagenie.ca
NAT64/DNS64 open-source --> http://ecdysis.viagenie.ca
STUN/TURN server --> http://numb.viagenie.ca
More information about the Ipv6hackers
mailing list