Re: Domain Centric Administration, RE: draft-ietf-v6ops-natpt-to-historic-00.txt

Joel Jaeggli <joelja@bogus.com> Tue, 03 July 2007 16:57 UTC

Return-path: <ietf-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1I5lh0-0005Eq-Q4; Tue, 03 Jul 2007 12:57:34 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1I5lgz-0005Ef-56 for ietf@ietf.org; Tue, 03 Jul 2007 12:57:33 -0400
Received: from [2001:418:1:0:230:48ff:fe82:537e] (helo=nagasaki.bogus.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1I5lgO-0007DS-KU for ietf@ietf.org; Tue, 03 Jul 2007 12:57:33 -0400
Received: from [192.103.16.81] ([192.103.16.81]) (authenticated bits=0) by nagasaki.bogus.com (8.14.1/8.13.8) with ESMTP id l63Gur3h052769; Tue, 3 Jul 2007 16:56:54 GMT (envelope-from joelja@bogus.com)
Message-ID: <468A7FC6.4080809@bogus.com>
Date: Tue, 03 Jul 2007 09:56:38 -0700
From: Joel Jaeggli <joelja@bogus.com>
User-Agent: Thunderbird 1.5.0.12 (X11/20070530)
MIME-Version: 1.0
To: Keith Moore <moore@cs.utk.edu>
References: <200707030410.l634ATg9059356@drugs.dv.isc.org> <20070703161328.42A5C233C7@coconut.itojun.org> <468A781F.8030506@cs.utk.edu>
In-Reply-To: <468A781F.8030506@cs.utk.edu>
X-Enigmail-Version: 0.94.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: ClamAV 0.90.2/3584/Tue Jul 3 07:44:39 2007 on nagasaki.bogus.com
X-Virus-Status: Clean
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 2409bba43e9c8d580670fda8b695204a
Cc: Mark_Andrews@isc.org, ietf@ietf.org
Subject: Re: Domain Centric Administration, RE: draft-ietf-v6ops-natpt-to-historic-00.txt
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Errors-To: ietf-bounces@ietf.org

Keith Moore wrote:
>
> word I hear is that Vista's enabling of such technologies is causing
> problems for enterprise networks because their traffic filters and
> intrusion detectors aren't set up to handle them.

It is trivial to filter teredo (knock down udp 3544) and I think you can
rest assured that enterprises are having no trouble doing so.
Organizations with internal default deny policies break teredo just like
they do everything else (I'm not advocating a position, just making an
observation).

If you want to selectively apply policy to packets inside encapsulated
teredo connections between clients you're going to have to do some work
(this applies generically to any tunneled protocol).

http://tools.ietf.org/html/draft-hoagland-v6ops-teredosecconcerns-00#section-3

joelja

> 
> _______________________________________________
> Ietf mailing list
> Ietf@ietf.org
> https://www1.ietf.org/mailman/listinfo/ietf
> 


_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf