Re: Forwarding Packets With Link Local Destination Addresses
Philip Homburg <pch-ipv6-ietf-7@u-1.phicoh.com> Fri, 08 January 2021 12:05 UTC
Return-Path: <pch-b9D3CB0F5@u-1.phicoh.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A79C3A0B1A for <ipv6@ietfa.amsl.com>; Fri, 8 Jan 2021 04:05:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.889
X-Spam-Level:
X-Spam-Status: No, score=-1.889 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, KHOP_HELO_FCRDNS=0.009, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id diWrOYGfi7Wq for <ipv6@ietfa.amsl.com>; Fri, 8 Jan 2021 04:05:16 -0800 (PST)
Received: from stereo.hq.phicoh.net (stereo6-tun.hq.phicoh.net [IPv6:2001:888:1044:10:2a0:c9ff:fe9f:17a9]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAE383A0B18 for <ipv6@ietf.org>; Fri, 8 Jan 2021 04:05:14 -0800 (PST)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (TLS version=TLSv1.2 cipher=ECDHE-RSA-CHACHA20-POLY1305) (Smail #157) id m1kxqW0-0000INC; Fri, 8 Jan 2021 13:05:12 +0100
Message-Id: <m1kxqW0-0000INC@stereo.hq.phicoh.net>
To: ipv6@ietf.org
Subject: Re: Forwarding Packets With Link Local Destination Addresses
From: Philip Homburg <pch-ipv6-ietf-7@u-1.phicoh.com>
Sender: pch-b9D3CB0F5@u-1.phicoh.com
References: <DM6PR05MB6348A18046C5DDC7CF2AED76AEAF0@DM6PR05MB6348.namprd05.prod.outlook.com> <fc2600de-308a-7162-db12-d1d906302494@si6networks.com> <CAJE_bqfSkvpT0PfbGxPmJ450+_DWH_66O9h=pbRkn36mB27sBA@mail.gmail.com> <3F8BB900-B77E-473D-8DF2-02FEA3E2BA32@tzi.org> <2b6e4c6e-b4ab-a23f-72f8-d91442331622@moth.iki.fi>
In-reply-to: Your message of "Fri, 8 Jan 2021 13:13:46 +0200 ." <2b6e4c6e-b4ab-a23f-72f8-d91442331622@moth.iki.fi>
Date: Fri, 08 Jan 2021 13:05:11 +0100
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/RolEKiPSGRKNkFPsSvUx0GQh2ds>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Jan 2021 12:05:19 -0000
In your letter dated Fri, 8 Jan 2021 13:13:46 +0200 you wrote: >I think the limitation (don't forward from higher scope to local on >routing header) should be kept and made extremely strong rule, >especially if the final address is a link local. No exceptions, ever. > >ND is already open to local attacks on local network, but this is >accepted. But, if random person on internet anywhere can inject ND >packets via routing header from outside the local network, it would be >very bad... It should not affect ND. ND requires the hop limit to be 255 on the receiving node. Beyond that, if routing headers do not cross security boundries, then I don't see a problem. If routing headers do cross security boundaries, then you may have bigger problems already.
- Re: Forwarding Packets With Link Local Destinatio… 神明達哉
- Forwarding Packets With Link Local Destination Ad… Ron Bonica
- RE: Forwarding Packets With Link Local Destinatio… Ron Bonica
- Re: Forwarding Packets With Link Local Destinatio… Fred Baker
- Re: Forwarding Packets With Link Local Destinatio… Alexandre Petrescu
- Re: Forwarding Packets With Link Local Destinatio… Fred Baker
- Re: Forwarding Packets With Link Local Destinatio… Alexandre Petrescu
- Re: Forwarding Packets With Link Local Destinatio… Toerless Eckert
- Re: Forwarding Packets With Link Local Destinatio… Brian E Carpenter
- Re: Forwarding Packets With Link Local Destinatio… Fernando Gont
- Re: Forwarding Packets With Link Local Destinatio… Gyan Mishra
- Re: Forwarding Packets With Link Local Destinatio… 神明達哉
- Re: Forwarding Packets With Link Local Destinatio… Alejandro Acosta
- Re: Forwarding Packets With Link Local Destinatio… 神明達哉
- Re: Forwarding Packets With Link Local Destinatio… Alexandre Petrescu
- Re: Forwarding Packets With Link Local Destinatio… Carsten Bormann
- Re: Forwarding Packets With Link Local Destinatio… Philip Homburg
- Re: Forwarding Packets With Link Local Destinatio… Markku Savela
- Re: Forwarding Packets With Link Local Destinatio… 神明達哉
- NATLL6 [was Re: Forwarding Packets With Link Loca… Brian E Carpenter
- Re: NATLL6 [was Re: Forwarding Packets With Link … Fernando Gont
- Re: NATLL6 [was Re: Forwarding Packets With Link … Brian E Carpenter
- Re: NATLL6 [was Re: Forwarding Packets With Link … Alejandro Acosta
- Re: NATLL6 [was Re: Forwarding Packets With Link … Alejandro Acosta