[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IETF IPv6 platform configuration
On 12-jun-2006, at 23:03, Pekka Savola wrote:
Is there a compelling reason to filter ICMP at all?
IMHO, this is a valid question.
Don't bother thinking about an answer, people are going to do it anyway.
An important problem with all kinds of filtering in IPv6 is that most
filters don't support the "protocol chain" concept so if you have a
fragment header or an AH header or some such between the IPv6 header
and the payload protocol, you're out of luck and the payload protocol
isn't recognized.
There also happens to be a document, draft-ietf-v6ops-icmpv6-
filtering-recs-00.txt that discusses this very issue. It might be
interesting to have folks read that and provide feedback to v6ops
list (v6ops@ops.ietf.org) if they think there's something amiss
with it.
Please use "hop limit" rather than "hop count" as the former is the
official name of the field.
And do we really need 34 pages just to say "if you're so paranoid
that you want to filter ICMPv6, at least have the sense to let these
ones through"?
We live in an age of information overload, conciseness is a virtue!