Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?

Ted Lemon <mellon@fugue.com> Wed, 24 April 2024 21:11 UTC

Return-Path: <mellon@fugue.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71990C14CEED for <ipv6@ietfa.amsl.com>; Wed, 24 Apr 2024 14:11:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.895
X-Spam-Level:
X-Spam-Status: No, score=-6.895 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yofyyP819c6t for <ipv6@ietfa.amsl.com>; Wed, 24 Apr 2024 14:11:54 -0700 (PDT)
Received: from mail-qv1-xf2a.google.com (mail-qv1-xf2a.google.com [IPv6:2607:f8b0:4864:20::f2a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14BC9C14F721 for <ipv6@ietf.org>; Wed, 24 Apr 2024 14:11:53 -0700 (PDT)
Received: by mail-qv1-xf2a.google.com with SMTP id 6a1803df08f44-6a05f376effso2965286d6.0 for <ipv6@ietf.org>; Wed, 24 Apr 2024 14:11:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20230601.gappssmtp.com; s=20230601; t=1713993112; x=1714597912; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=3KSbUR22f5fDY5LTZ+MN+K1plXIHuUGnpQfsatedzE8=; b=hsfGPLW275g2UVyrXtIQbBKnIJYoHmw7CFiKm1vAPpQa2KXM9iD4dGbMjS5fxF0atm U0Mrz5QnxMQq3/uwClwfuhpyIXI0k3WU4zpHw5x/kSg6aN58H982Kk+p22dCDDIkQac6 aA2WJJNPd+B0DDiJUo/j1TPnnmUUgklO7nzENk5wMinTJw+oYxkR/stBIXUVOidFVWw4 JJXnekJKMueeZAmFfSY8Q1se7LvjTporMW9nFOkRNjJ3NoCoFwySHB83zX+CKqhr1+IS Ymv+QVbMHvott5PgAPgrGGoc8JuKimufJEBQVMbCG9X4DuPeXO4mFWV2k29LY2EBL4JE 3xvg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713993112; x=1714597912; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=3KSbUR22f5fDY5LTZ+MN+K1plXIHuUGnpQfsatedzE8=; b=bKkACEDm/8TjWKvx1haChtvgYTwwyW70zXgI2Cm4mFRWm8cZtCOOJTvom9F+zAhGrK ok/EP1R5oSY/CiVZ03X9xHneIFdePdzGk8uxX0Fqjys0qpNurXee+dvq0wyY0DTAHXem oBYrCYlSFjkqeUPDzKWoLvrE1u+OqerbZ6OU7YALwM0AttbbxfaH2tIPrnwpNkZuwMsJ uGxe/nh75tWmLyCNVBFj1ho+TOowWaQN5wwalDfySmaNxwVjAYyD3V9CoWsPGhz4bk5Q nH2ujuJKxKhCdbtl3LaK55L4UsgTbcxcnCrn6WXgCPhD1tTzisITLnh/o9EvxsGlzmur 04kw==
X-Forwarded-Encrypted: i=1; AJvYcCX1ZPffKwkg3RlvluQcLpgyTm/FlNL6CWY7Pni5gFpYVg5r8rqsOZ+WUnvjRaDEeTL3LqPuIXKNfOAtMtqU
X-Gm-Message-State: AOJu0YwHAk9Vm2fbuM1/xO2MezYiBpbhGsCw16cUKQ+EHCAA8lwmqbdr V35l5B2A/HKGGJxaYaOEs+G0/9QgqHi+ZYuXvjhCq0DPuY0jjNQQUhmzojFXWq+oLdxcBMw1GMT rZUH2AQTXiziq0lt/vBhL1HgqBTzwnBtZygvmog==
X-Google-Smtp-Source: AGHT+IE7ufopCFXmwFLj4oQA4L3DcReykkRmpqlKw1EjmBYcEg+WdIj0koxQPpB+C6eaJoOmCKhr7epHQlv4r5QgvCI=
X-Received: by 2002:a05:6214:118b:b0:6a0:4169:9cf2 with SMTP id t11-20020a056214118b00b006a041699cf2mr3483680qvv.36.1713993112495; Wed, 24 Apr 2024 14:11:52 -0700 (PDT)
MIME-Version: 1.0
References: <CAMkkUf3UqjJbuBQwvaOAsV=4VwPYBCUTBNLfUB2ZF4gAv4CHnQ@mail.gmail.com> <D4424AFD-CE28-46C8-808E-A41979973DA4@isc.org> <CAMkkUf1brxg1DhPiv-93PtN1pOyGsGhLopGbxTW6jgz+c92wTA@mail.gmail.com> <23BC33A7-5BF5-4F14-B29A-D5FBCC587DD2@puck.nether.net>
In-Reply-To: <23BC33A7-5BF5-4F14-B29A-D5FBCC587DD2@puck.nether.net>
From: Ted Lemon <mellon@fugue.com>
Date: Wed, 24 Apr 2024 17:11:41 -0400
Message-ID: <CAPt1N1kejdWo9AXOiO-4+TQHi442zgEd565uS-bRz-ioqPrA3w@mail.gmail.com>
To: Jared Mauch <jared@puck.nether.net>
Cc: 6lo@ietf.org, 6man <ipv6@ietf.org>, Hubert W <hubert.wisniewski@gmail.com>, Mark Andrews <marka@isc.org>
Content-Type: multipart/alternative; boundary="0000000000009e4b1b0616de1e07"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/OCvJHFVDu9WG4G693cYDtSWfqss>
Subject: Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Apr 2024 21:11:56 -0000

Sounds a lot like PCP…

Op wo 24 apr 2024 om 16:26 schreef Jared Mauch <jared@puck.nether.net>

> I had thought of doing something where the device could send a profile to
> the router/DHCP server that says “here’s the ports, dns names, etc.. that I
> will be using”.
>
> This would then permit only those related bits to flow.
>
> - Jared
>
> > On Apr 24, 2024, at 4:23 PM, Hubert W <hubert.wisniewski@gmail.com>
> wrote:
> >
> >
> >
> > On Wed, Apr 24, 2024, 07:46 Mark Andrews <marka@isc.org> wrote:
> >
> >
> > > On 23 Apr 2024, at 16:51, Hubert W <hubert.wisniewski@gmail.com>
> wrote:
> > >
> > > Dear WG,
> > >
> > >
> > > I woke up with one idea and I would like to challenge it.
> > > In IPv6, every device receives a routable address. To protect
> endpoints effectively, we require firewalls to filter unwanted traffic.
> >
> > Apart from packet volume this is a false assertion.  No device should
> require a firewall.
> >
> > > But what if we could stop such traffic at the source? Could this
> approach convince more people toward adopting IPv6?
> > >
> > > According to RFC 7381: “In a /48 assignment, typical for a site, there
> are then still 65,535 /64 blocks.” and “All user access networks should be
> a /64.”
> >
> > /64 is typical not required.
> >
> > > Can we use then bit 63 to convey a message: “I don’t want any incoming
> traffic initiated towards me!!!”? Of course a response would be accepted.
> > >
> > > We could divide the /64 allocations into two groups: one for servers,
> and these accept incoming traffic (bit 63 = 0):
> > >
> > > for example 2001:0db8:0000:0000::/64
> > >
> > > And the second group: endpoints, these never accept incoming traffic
> (bit 63 = 1):
> > >
> > > for example 2001:0db8:0000:0001::/64
> > >
> > > We only need all systems to understand the message. If a router or
> firewall sees such a packet, then drops it.
> > > Every TCP packet with flag SYN, where destination address (IPv6) has
> bit 63 equal 1, must be dropped.
> >
> > All the world is not TCP.  Additionally for TCP the filtering device
> would need to track state and that implies symmetric routing.
> >
> > > Would it be theoretically possible?
> >
> > No.
> >
> > > Best regards
> > >
> > > Hubert Wisniewski
> > >
> > > --------------------------------------------------------------------
> > > IETF IPv6 working group mailing list
> > > ipv6@ietf.org
> > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> > > --------------------------------------------------------------------
> >
> > --
> > Mark Andrews, ISC
> > 1 Seymour St., Dundas Valley, NSW 2117, Australia
> > PHONE: +61 2 9871 4742              INTERNET: marka@isc.org
> > I think there would be no issue with asymmetric traffic if we only check
> SYN flag, but I understand that is not a good idea. Thank you for your
> opinion.
> >
> > Hubert Wisniewski
> > --------------------------------------------------------------------
> > IETF IPv6 working group mailing list
> > ipv6@ietf.org
> > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> > --------------------------------------------------------------------
>
>
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> --------------------------------------------------------------------
>