[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: source address rewriting and shim6 proxies
marcelo bagnulo braun wrote:
but this would mean that you would be accepting packets with any source
address? wouldn't be some serious security issues there?
Depends how hard it would be to guess the context tag. Only nodes on the
path between A and B would know the context tag that B told A to use.
And those nodes can use A's source addresses even if there is ingress
filtering, since they are on the path.
Oh - doing router rewriting of the source address presumably implies
that every data packet (even before a locator switch) have to carry a
context tag, since the router can change the source locator on any packet.
Erik