Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?
Ted Lemon <mellon@fugue.com> Wed, 24 April 2024 21:11 UTC
Return-Path: <mellon@fugue.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71990C14CEED for <ipv6@ietfa.amsl.com>; Wed, 24 Apr 2024 14:11:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.895
X-Spam-Level:
X-Spam-Status: No, score=-6.895 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yofyyP819c6t for <ipv6@ietfa.amsl.com>; Wed, 24 Apr 2024 14:11:54 -0700 (PDT)
Received: from mail-qv1-xf2a.google.com (mail-qv1-xf2a.google.com [IPv6:2607:f8b0:4864:20::f2a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14BC9C14F721 for <ipv6@ietf.org>; Wed, 24 Apr 2024 14:11:53 -0700 (PDT)
Received: by mail-qv1-xf2a.google.com with SMTP id 6a1803df08f44-6a05f376effso2965286d6.0 for <ipv6@ietf.org>; Wed, 24 Apr 2024 14:11:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20230601.gappssmtp.com; s=20230601; t=1713993112; x=1714597912; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=3KSbUR22f5fDY5LTZ+MN+K1plXIHuUGnpQfsatedzE8=; b=hsfGPLW275g2UVyrXtIQbBKnIJYoHmw7CFiKm1vAPpQa2KXM9iD4dGbMjS5fxF0atm U0Mrz5QnxMQq3/uwClwfuhpyIXI0k3WU4zpHw5x/kSg6aN58H982Kk+p22dCDDIkQac6 aA2WJJNPd+B0DDiJUo/j1TPnnmUUgklO7nzENk5wMinTJw+oYxkR/stBIXUVOidFVWw4 JJXnekJKMueeZAmFfSY8Q1se7LvjTporMW9nFOkRNjJ3NoCoFwySHB83zX+CKqhr1+IS Ymv+QVbMHvott5PgAPgrGGoc8JuKimufJEBQVMbCG9X4DuPeXO4mFWV2k29LY2EBL4JE 3xvg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713993112; x=1714597912; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=3KSbUR22f5fDY5LTZ+MN+K1plXIHuUGnpQfsatedzE8=; b=bKkACEDm/8TjWKvx1haChtvgYTwwyW70zXgI2Cm4mFRWm8cZtCOOJTvom9F+zAhGrK ok/EP1R5oSY/CiVZ03X9xHneIFdePdzGk8uxX0Fqjys0qpNurXee+dvq0wyY0DTAHXem oBYrCYlSFjkqeUPDzKWoLvrE1u+OqerbZ6OU7YALwM0AttbbxfaH2tIPrnwpNkZuwMsJ uGxe/nh75tWmLyCNVBFj1ho+TOowWaQN5wwalDfySmaNxwVjAYyD3V9CoWsPGhz4bk5Q nH2ujuJKxKhCdbtl3LaK55L4UsgTbcxcnCrn6WXgCPhD1tTzisITLnh/o9EvxsGlzmur 04kw==
X-Forwarded-Encrypted: i=1; AJvYcCX1ZPffKwkg3RlvluQcLpgyTm/FlNL6CWY7Pni5gFpYVg5r8rqsOZ+WUnvjRaDEeTL3LqPuIXKNfOAtMtqU
X-Gm-Message-State: AOJu0YwHAk9Vm2fbuM1/xO2MezYiBpbhGsCw16cUKQ+EHCAA8lwmqbdr V35l5B2A/HKGGJxaYaOEs+G0/9QgqHi+ZYuXvjhCq0DPuY0jjNQQUhmzojFXWq+oLdxcBMw1GMT rZUH2AQTXiziq0lt/vBhL1HgqBTzwnBtZygvmog==
X-Google-Smtp-Source: AGHT+IE7ufopCFXmwFLj4oQA4L3DcReykkRmpqlKw1EjmBYcEg+WdIj0koxQPpB+C6eaJoOmCKhr7epHQlv4r5QgvCI=
X-Received: by 2002:a05:6214:118b:b0:6a0:4169:9cf2 with SMTP id t11-20020a056214118b00b006a041699cf2mr3483680qvv.36.1713993112495; Wed, 24 Apr 2024 14:11:52 -0700 (PDT)
MIME-Version: 1.0
References: <CAMkkUf3UqjJbuBQwvaOAsV=4VwPYBCUTBNLfUB2ZF4gAv4CHnQ@mail.gmail.com> <D4424AFD-CE28-46C8-808E-A41979973DA4@isc.org> <CAMkkUf1brxg1DhPiv-93PtN1pOyGsGhLopGbxTW6jgz+c92wTA@mail.gmail.com> <23BC33A7-5BF5-4F14-B29A-D5FBCC587DD2@puck.nether.net>
In-Reply-To: <23BC33A7-5BF5-4F14-B29A-D5FBCC587DD2@puck.nether.net>
From: Ted Lemon <mellon@fugue.com>
Date: Wed, 24 Apr 2024 17:11:41 -0400
Message-ID: <CAPt1N1kejdWo9AXOiO-4+TQHi442zgEd565uS-bRz-ioqPrA3w@mail.gmail.com>
To: Jared Mauch <jared@puck.nether.net>
Cc: 6lo@ietf.org, 6man <ipv6@ietf.org>, Hubert W <hubert.wisniewski@gmail.com>, Mark Andrews <marka@isc.org>
Content-Type: multipart/alternative; boundary="0000000000009e4b1b0616de1e07"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/OCvJHFVDu9WG4G693cYDtSWfqss>
Subject: Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Apr 2024 21:11:56 -0000
Sounds a lot like PCP… Op wo 24 apr 2024 om 16:26 schreef Jared Mauch <jared@puck.nether.net> > I had thought of doing something where the device could send a profile to > the router/DHCP server that says “here’s the ports, dns names, etc.. that I > will be using”. > > This would then permit only those related bits to flow. > > - Jared > > > On Apr 24, 2024, at 4:23 PM, Hubert W <hubert.wisniewski@gmail.com> > wrote: > > > > > > > > On Wed, Apr 24, 2024, 07:46 Mark Andrews <marka@isc.org> wrote: > > > > > > > On 23 Apr 2024, at 16:51, Hubert W <hubert.wisniewski@gmail.com> > wrote: > > > > > > Dear WG, > > > > > > > > > I woke up with one idea and I would like to challenge it. > > > In IPv6, every device receives a routable address. To protect > endpoints effectively, we require firewalls to filter unwanted traffic. > > > > Apart from packet volume this is a false assertion. No device should > require a firewall. > > > > > But what if we could stop such traffic at the source? Could this > approach convince more people toward adopting IPv6? > > > > > > According to RFC 7381: “In a /48 assignment, typical for a site, there > are then still 65,535 /64 blocks.” and “All user access networks should be > a /64.” > > > > /64 is typical not required. > > > > > Can we use then bit 63 to convey a message: “I don’t want any incoming > traffic initiated towards me!!!”? Of course a response would be accepted. > > > > > > We could divide the /64 allocations into two groups: one for servers, > and these accept incoming traffic (bit 63 = 0): > > > > > > for example 2001:0db8:0000:0000::/64 > > > > > > And the second group: endpoints, these never accept incoming traffic > (bit 63 = 1): > > > > > > for example 2001:0db8:0000:0001::/64 > > > > > > We only need all systems to understand the message. If a router or > firewall sees such a packet, then drops it. > > > Every TCP packet with flag SYN, where destination address (IPv6) has > bit 63 equal 1, must be dropped. > > > > All the world is not TCP. Additionally for TCP the filtering device > would need to track state and that implies symmetric routing. > > > > > Would it be theoretically possible? > > > > No. > > > > > Best regards > > > > > > Hubert Wisniewski > > > > > > -------------------------------------------------------------------- > > > IETF IPv6 working group mailing list > > > ipv6@ietf.org > > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > > > -------------------------------------------------------------------- > > > > -- > > Mark Andrews, ISC > > 1 Seymour St., Dundas Valley, NSW 2117, Australia > > PHONE: +61 2 9871 4742 INTERNET: marka@isc.org > > I think there would be no issue with asymmetric traffic if we only check > SYN flag, but I understand that is not a good idea. Thank you for your > opinion. > > > > Hubert Wisniewski > > -------------------------------------------------------------------- > > IETF IPv6 working group mailing list > > ipv6@ietf.org > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > > -------------------------------------------------------------------- > > > -------------------------------------------------------------------- > IETF IPv6 working group mailing list > ipv6@ietf.org > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > -------------------------------------------------------------------- >
- [IPv6] Can We Turn the Global Network into a Fire… Hubert W
- Re: [IPv6] Can We Turn the Global Network into a … Mark Andrews
- Re: [IPv6] Can We Turn the Global Network into a … Hubert W
- Re: [IPv6] Can We Turn the Global Network into a … Jared Mauch
- Re: [IPv6] Can We Turn the Global Network into a … Ted Lemon