[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IETF multihoming powder: just add IPv6 and stir



Tony Li wrote:
> 
> A filter that is looking at a locator is probably a bug.

In that case there will be many bugs. Similar issues arise
for QOS classifiers (unless we get the flow label into general
use).

   Brian

> 
> Tony
> 
> |    On dinsdag, mei 13, 2003, at 23:37 Europe/Amsterdam, Masataka Ohta
> |    wrote:
> |
> |    > OTOH, rewriting of source locator is not so useful, though I have
> |    > no reason to forbid it.
> |
> |    Unless the source address is already a valid address
> |    assigned by the
> |    ISP you're forwarding the packet to (which can't by
> |    definition always
> |    be the case in a locator/identifier scheme), you need to
> |    rewrite it in
> |    order to get through ingress filtering and to be able to
> |    receive ICMP
> |    messages. Remember that path MTU discovery is pretty much
> |    mandatory in
> |    IPv6 so you need those ICMPs. Ingress filtering is
> |    important to keep
> |    denial of service attacks in check to at least some degree.