[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-wbeebee-ipv6-cpe-router-04 comments



On Thu, 26 Mar 2009, Mark Smith wrote:

I agree with James. An implementation model of ADSL with Ethernet backhaul (TR-101) is to have all CPE sitting in the same "bridged Ethernet over ADSL" VLAN, ethernet switched in the local telephone exchange / C.O., with the default router off site, also in the same VLAN. Having the CPE announce their prefixes to each other would keep inter-CPE traffic off of the expensive backhaul links. If P2P applications/traffic become much more locality aware, this would be of great benefit.

This sound like a huge security problem, how are those implications handled? Wouldn't the L2 device in the CO need to be able to inspect all these messages and drop ones which are not assigned to that specific customer by the ISP?

In the scenarios I have seen before mechanisms such as forced forwarding and/or mac rewrite/DHCP snooping based ACLs been used in the CO L2 device to handle this, what are the IPv6 equivalents in this scenario?

--
Mikael Abrahamsson    email: swmike@swm.pp.se