[IPv6]Re: Fe80::/10 sources
Mark Smith <markzzzsmith@gmail.com> Wed, 09 April 2025 22:44 UTC
Return-Path: <markzzzsmith@gmail.com>
X-Original-To: ipv6@mail2.ietf.org
Delivered-To: ipv6@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 12B4419DC0B6 for <ipv6@mail2.ietf.org>; Wed, 9 Apr 2025 15:44:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.598
X-Spam-Level:
X-Spam-Status: No, score=-0.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, FROM_LOCAL_NOVOWEL=0.5, HK_RANDOM_ENVFROM=0.001, HK_RANDOM_FROM=0.999, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oayOzCdVwQ6R for <ipv6@mail2.ietf.org>; Wed, 9 Apr 2025 15:44:34 -0700 (PDT)
Received: from mail-pj1-x1035.google.com (mail-pj1-x1035.google.com [IPv6:2607:f8b0:4864:20::1035]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 65D8D19DC0B1 for <ipv6@ietf.org>; Wed, 9 Apr 2025 15:44:34 -0700 (PDT)
Received: by mail-pj1-x1035.google.com with SMTP id 98e67ed59e1d1-301918a4e3bso158760a91.3 for <ipv6@ietf.org>; Wed, 09 Apr 2025 15:44:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1744238673; x=1744843473; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=RBAwBoB1YlQCvJyQI0Gd0p7ocukd0r90WurWkjcTQ7c=; b=aUa2CxPcRVjyZdgd+YQb2tgdO09K9Va9xj7C3aqNDWiGxOgOS8BrYIbXV3IVXR7A0s CFRX4kXlxl/iNzs9DpS7x762hQgDrg50c2UPXcMSaEZ9HTp/hYamo4qrzvtv7n53tDez YiMLcPMdgdk/stQI8kowLZ7TLoMr9F/Z6uCduaKrcrwFCPg5Kh1OKp1T7cfjAFcd06EO yt9qdXO6b+D7NsglR0JvgS3hEE501MbD7E0x2V1DlfWJv30CvXTdbHSGGl6YGXEMQrqw qq1TtE7LPIE7x5KTJZQjPQgb9o7Sm5glawbNiFDBNVT+uQUb//81qZxrkMQQvFGn//2R XpFQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744238673; x=1744843473; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=RBAwBoB1YlQCvJyQI0Gd0p7ocukd0r90WurWkjcTQ7c=; b=mq+QBNrtvTwXqf9keJsvkiSQSxKgTPMZBuUmTecPgKSCugeiN1Hwawdm7SqozE7cGm RkoLJlCJOSU2ddYEpoq5BkH4kUhT2PnOtdpWNWiHPH2ZFojDGm4/DR3mmRrBV3Ooqa9e 7UrHSJm2wk+kJ/csr/Y2nh/Ag4uUeXIXrIwVnlsbfSzA5rugcWbc4PW4l4GgvQs5EZE5 nnR1AymlJ42ib+J0YTZx7+PmsXlSkWj007sv2ZlPSK57RzyEx3X06+pJVLkBl1rGk3mi JP90XfQ4PuXehKwxuWlY5ZAKcnT+fkV3EztUWqLgH/X40ecEgQxSDRXk433A1lcRyWfl IvCw==
X-Forwarded-Encrypted: i=1; AJvYcCUzpDZeUVLPWF0tBbjAJ/biAwjc0kZCBbqzgNZhTWcQYeUvyvc3tdz/gl4R/pIurZpFA49B@ietf.org
X-Gm-Message-State: AOJu0Yzd60UaHRSIKaLFSVePwzQfar98BgIUA7l+wrpyTvdsLVqGr0nD BJ9pbsUOlBGzIYrsRPYcFNzQM1ODiRzBz7ZqsW9mL0FQyzkukAydXIZDCJhhLZt5K5KJU1vU7bB 8IcW+kxznBqwwBdqigON6ZBDVpw8=
X-Gm-Gg: ASbGncstP/MX4mzSk0bz7H6XFAINOECvo21SJZOsgMCDdF+U6Up4/SAGlqMq5YzQ8aU msDmd52tEaAPVNv/SUl+288xxMF78MT3+loA65kSr15oW2xPx2Y5Nlf862TpseSLwCp3oRoTRhM 1JhN53Kpu0n+b86WptWFaiGvs=
X-Google-Smtp-Source: AGHT+IHMLRoeQO/q7I7io2baZ4g63ioR7yA7HpgWSKA5EuQ8bD7ZP23SQG8rUupekD0K3yqwzXdBjpFjiVxDpSHD7I4=
X-Received: by 2002:a17:90a:d64e:b0:2ee:edae:75e with SMTP id 98e67ed59e1d1-307e596f751mr295534a91.13.1744238673303; Wed, 09 Apr 2025 15:44:33 -0700 (PDT)
MIME-Version: 1.0
References: <FD4E0420-6347-41A0-9AA8-A4B9271C5503@puck.nether.net> <CAFU7BATtEFdd4A1w4kK+AcvhFch6G=aGhVaOZJSCjdFzq-L91g@mail.gmail.com> <Z_UyiIV_OouVB7Fx@puck.nether.net> <CAJU8_nVEOiqN4PaHU0KgPSkG=Gj0HickKJJaG15Nx+FsJetCCg@mail.gmail.com> <9B07CD06-FC65-4FA8-8604-3914A37CFEB2@puck.nether.net> <CAJU8_nU6KVuu7PVCLRUZj1KQJFHVQhDXVxZKCV4cHfM4iWgqGA@mail.gmail.com> <CAN-Dau3OsVsLF1_4aRxirTXqPJvoCUP84o7tLEuL+6ARcU-2bA@mail.gmail.com> <CAJU8_nWS-XTGE1sj_cneroYz6Bq0HQmbTPc7YXeB+=X9c9prkQ@mail.gmail.com> <CAN-Dau3segoB31T7paGEZSTHFskhy_edzvyU=cKCObqnXAfDpg@mail.gmail.com> <60c1e8e5-7a49-4cea-b83f-296384ba9a0b@app.fastmail.com> <Z_Wgl_kBEpojmgxQ@puck.nether.net> <CAO42Z2y3S=DewQx=_WPX2vAmvGQTvBYgj6PEZng+7iV83T5NWA@mail.gmail.com> <CAN-Dau0MovBovVXrR+FwVFB0zhx6SQc0i6OKefffVbDLZBzm7g@mail.gmail.com>
In-Reply-To: <CAN-Dau0MovBovVXrR+FwVFB0zhx6SQc0i6OKefffVbDLZBzm7g@mail.gmail.com>
From: Mark Smith <markzzzsmith@gmail.com>
Date: Thu, 10 Apr 2025 10:44:21 +1200
X-Gm-Features: ATxdqUF_-pfnRLRgp99aGtZ662noWcSR3XVU6G0VhLOo4yBkW8kYqzY0B-vrh_I
Message-ID: <CAO42Z2zxVcpV_PzofGkYq6RbsPUo0=9Twd5wTtAbRRdror0NLQ@mail.gmail.com>
To: David Farmer <farmer@umn.edu>
Content-Type: multipart/alternative; boundary="00000000000086a59906326036e7"
Message-ID-Hash: QZ6B365F3D63YSBJVDJBHBZDGZX3YPQJ
X-Message-ID-Hash: QZ6B365F3D63YSBJVDJBHBZDGZX3YPQJ
X-MailFrom: markzzzsmith@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipv6.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF IPv6 Mailing List <ipv6@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPv6]Re: Fe80::/10 sources
List-Id: "IPv6 Maintenance Working Group (6man)" <ipv6.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/IiQ_mYrBqeSBWCDrjNu0Lw8sSgg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Owner: <mailto:ipv6-owner@ietf.org>
List-Post: <mailto:ipv6@ietf.org>
List-Subscribe: <mailto:ipv6-join@ietf.org>
List-Unsubscribe: <mailto:ipv6-leave@ietf.org>
Hi, On Wed, 9 Apr 2025, 13:10 David Farmer, <farmer@umn.edu> wrote: > UOn Tue, Apr 8, 2025 at 18:11 Mark Smith <markzzzsmith@gmail.com> wrote: > >> >> On Wed, 9 Apr 2025, 08:18 Jared Mauch, <jared@puck.nether.net> wrote: >> >>> On Tue, Apr 08, 2025 at 08:39:47PM +0200, Ted Lemon wrote: >>> > That’s a bug in the mdns implementation. It should be fixed rather >>> than >>> > worked around. >>> > But I do agree that generally blocking packets with bogus source >>> addresses >>> > at the router is better than requiring hosts to do the right thing, >>> not >>> > because we shouldn’t but because hosts get hacked, sometimes en >>> masse, and >>> > so the routers still have to do the right thing. In which case >>> having >>> > hosts do the wrong thing actually is good because it exercises >>> this. >>> >>> Not arguging with your scenario at all, but should hosts send >>> traffic out with LL source and HOP_LIMIT NOT IN (1,255)? >> >> >> If the HL is set to 1, and a router receives it, per RFC8200 the router >> will then drop the packet after decrementing the HL to zero. The router >> will then generate an ICMPv6 Time Exceeded Message. >> > > What about a compromise, setting HL = 2? If the host forwards the packet > to the router, the router can send it back to the local interface if > appropriate. But if it forwards it onto another router, inappropriately, it > will have HL = 1 and the next router will decrement to HL = 0 and drop the > packet. > That router won't just drop the packet, it will also generate an ICMPv6 Packet Too Big message, destined to the LLA DA that is unreachable, so the PTB will never be reach the node that sent the LLA SA packet that triggered it, because the LLA is one hop away in the reverse direction. Each of those ICMPv6 PTBs is control plane load. With enough of these packets that could have a control plane processing impact. Another issue is that ICMPv6 is rate limited. These LLA SA packets that are generating PTBs on the 2nd hop upstream router could exceed the ICMPv6 rate limit, and that could mean either no ICMPv6 messages from that router, or no ICMPV6 PTBs where those PTBs would reach the node that triggered them (i.e. GUA or ULA SA trigger packets). Are these LLS SA packets really that much of an issue? They've come up before on the mailing lists, perhaps about 10 years ago. I've seen them in production about 5 years ago. Regards, Mark. > Not a perfect solution, but at least it contains how far the forwarded > Link-Local packet gets, even if the routers don't implement RFC4291, > section 2.5.6 correctly. > > Can we work with that? > > Thanks > > The HL 255 trick only works if the receiving node checks for a HL of 255. >> In this situation it would be a router having to check each and every >> packet it receives for possible forwarding for both an LLA SA and a HL == >> 255. >> >> I think ingress ACL checking SAs or BCP38 filters is a more effective >> solution than updating all IPv6 hosts to either HL=1 and HL=255 for this >> situation. >> >> Regards, >> Mark. >> >> >> I'm not >>> convinced the host doesn't have an equal partnership in this ecosystem. >>> >>> There appears to be wrong and bad behavior all over, and this is >>> one of the threads that I'm pulling on related to the behavior. To be >>> clear this is a real observed behavior, not some hypothetical straw-man. >>> >>> - Jared >> >> >>> >>> -- >>> Jared Mauch | pgp key available via finger from jared@puck.nether.net >>> clue++; | http://puck.nether.net/~jared/ My statements are only >>> mine. >>> >>> -------------------------------------------------------------------- >>> IETF IPv6 working group mailing list >>> ipv6@ietf.org >>> List Info: https://mailman3.ietf.org/mailman3/lists/ipv6@ietf.org/ >>> -------------------------------------------------------------------- >>> >>
- [IPv6]Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Kyle Rose
- [IPv6]Re: Fe80::/10 sources Jen Linkova
- [IPv6]Re: Fe80::/10 sources Lorenzo Colitti
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Kyle Rose
- [IPv6]Re: Fe80::/10 sources Ted Lemon
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Kyle Rose
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Erik Nygren
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Bob Hinden
- [IPv6]Re: Fe80::/10 sources Mark Smith
- [IPv6]Re: Fe80::/10 sources Nick Buraglio
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Ted Lemon
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Mark Smith
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Adnan Rashid
- [IPv6]Re: Fe80::/10 sources Brian E Carpenter
- [IPv6]Re: Fe80::/10 sources Brian E Carpenter
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Brian E Carpenter
- [IPv6]Re: Fe80::/10 sources Michael Richardson
- [IPv6]Re: Fe80::/10 sources Brian E Carpenter
- [IPv6]Re: Fe80::/10 sources Mark Smith
- [IPv6]Re: Fe80::/10 sources Ted Lemon
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Timothy Winters
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Jen Linkova
- [IPv6]Re: Fe80::/10 sources Erik Kline
- [IPv6]Re: Fe80::/10 sources Jen Linkova
- [IPv6]Re: Fe80::/10 sources David Farmer
- [IPv6]Re: Fe80::/10 sources Jen Linkova
- [IPv6]Re: Fe80::/10 sources Jared Mauch
- [IPv6]Re: Fe80::/10 sources Brian E Carpenter
- [IPv6]Re: Fe80::/10 sources Mark Smith
- [IPv6]Re: Fe80::/10 sources David Farmer