[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: An alternative to 6to4 and teredo




-- dimanche, janvier 19, 2003 22:52:20 +0100 Erik Nordmark
<Erik.Nordmark@sun.com> wrote/a écrit:

>> OTOH, I think tunnel broker is a good way to provide default route for a
>> 6to4 site.
> 
> That would make the site be multi-addressed with a 6to4 prefix
> plus a prefix that was assigned by the tunnel broker.
> 
> That raises questions of what source address filtering might be
> appropriate at the tunnel server - should they accept any source address?

tunnel server is implementing "configured tunnels", so strictly speaking,
only configured tunnels are "accepted".

> That would seem counter to the arguments about 6to4 relays introducing
> new ways to spoof source addresses - the tunnel server would
> in essence to the same.
> 
> Unless there was a way to register an alternate source address prefix
> with the tunnel broker as part of configuring the tunnel broker ...

could be done, since the 6to4 prefix is derived from the ipv4 address of
the source, which is also the source address of the tsp request and the
tunnel endpoint.

Marc.

> 
>   Erik
>