[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: source address rewriting and shim6 proxies



marcelo bagnulo braun wrote:

but this would mean that you would be accepting packets with any source address? wouldn't be some serious security issues there?

Depends how hard it would be to guess the context tag. Only nodes on the path between A and B would know the context tag that B told A to use. And those nodes can use A's source addresses even if there is ingress filtering, since they are on the path.

Oh - doing router rewriting of the source address presumably implies that every data packet (even before a locator switch) have to carry a context tag, since the router can change the source locator on any packet.

  Erik