Re: -06 candidate

Brian E Carpenter <brian.e.carpenter@gmail.com> Wed, 18 January 2012 02:52 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 97FAB21F8486 for <ipv6@ietfa.amsl.com>; Tue, 17 Jan 2012 18:52:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.521
X-Spam-Level:
X-Spam-Status: No, score=-103.521 tagged_above=-999 required=5 tests=[AWL=0.078, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JJCZVFCfAs9k for <ipv6@ietfa.amsl.com>; Tue, 17 Jan 2012 18:52:03 -0800 (PST)
Received: from mail-gx0-f172.google.com (mail-gx0-f172.google.com [209.85.161.172]) by ietfa.amsl.com (Postfix) with ESMTP id 2D60C21F86C3 for <ipv6@ietf.org>; Tue, 17 Jan 2012 18:52:03 -0800 (PST)
Received: by ggnr5 with SMTP id r5so4204699ggn.31 for <ipv6@ietf.org>; Tue, 17 Jan 2012 18:52:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=message-id:date:from:organization:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=ps9Is6dlR9/IYNx+RGj/xF1wTXDKlg7bkmdlPuslXJs=; b=gs8Ab5xdDnc/dyI0Q4ljF96UeMxrb6ztBb4Gb7JyHOKlPnaAZ8QZs4NGJizLlr9y3r jhxClI/pMKf+H11JMmacwTz/BS1P9VkGv2PTITl9D/JcyRIIfG9/17pAnsPTiVPhUaEi IWUydMY9oQsCzasKjHFbyJwJEdHhfUEYhwedo=
Received: by 10.100.231.4 with SMTP id d4mr4625166anh.37.1326855122785; Tue, 17 Jan 2012 18:52:02 -0800 (PST)
Received: from [130.216.38.124] (stf-brian.sfac.auckland.ac.nz. [130.216.38.124]) by mx.google.com with ESMTPS id u9sm65498545anh.20.2012.01.17.18.51.58 (version=SSLv3 cipher=OTHER); Tue, 17 Jan 2012 18:52:01 -0800 (PST)
Message-ID: <4F1633D7.7050709@gmail.com>
Date: Wed, 18 Jan 2012 15:52:07 +1300
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
MIME-Version: 1.0
To: Mark Andrews <marka@isc.org>
Subject: Re: -06 candidate
References: <4EB3F3D6.4090302@innovationslab.net> <CAC1-dtnas++ahkBmpdyq7DbyAEg0W6bZY16qGzKmsP10vC39FQ@mail.gmail.com> <4EEA3D20.7020603@innovationslab.net> <CAKFn1SFvs0PzBXtEWWo814Oe5TJmbQEJBm5FeYJY5xzrr=KFSw@mail.gmail.com> <4EEA5793.8080800@gmail.com> <CAKFn1SHA-=cQ_=5rJVLVMvQYXoTL_D1dCR=uWZK-qFrcGp6P-w@mail.gmail.com> <4EEA7AF8.2090508@gmail.com> <0D0150C3-9E05-4839-ACF1-0E7196420D2F@ecs.soton.ac.uk> <CAKFn1SFp_r7EJ6CpM8EF2zkcJz1z34CdEcRt2i5xcsrWkCBQwQ@mail.gmail.com> <EMEW3|bd681ced736eee0700e443f9acc256d8nBFAnB03tjc|ecs.soton.ac.uk|0D0150C3-9E05-4839-ACF1-0E7196420D2F@ecs.soton.ac.uk> <CAC1-dtnt+NKnqJaj-osfxwDf=uLpfv62hBBGDzftGL8KA6jdEA@mail.gmail.com> <6DDA8D20-8D10-4B6E-B101-9812FD83B781@nttv6.net> <20120117222653.99F9C1B88A6D@drugs.dv.isc.org>
In-Reply-To: <20120117222653.99F9C1B88A6D@drugs.dv.isc.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Cc: Tim Chown <tjc@ecs.soton.ac.uk>, draft-ietf-6man-rfc3484-revise@tools.ietf.org, 6man Mailing List <ipv6@ietf.org>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jan 2012 02:52:05 -0000

On 2012-01-18 11:26, Mark Andrews wrote:
> ULA need to be de-preferenced except for the local ULA prefixes.
> 
> Below is what I use in FreeBSD 8.  It keeps local traffic using
> fd92:7065:b8e::/48 rather than using the PA address.  If you learn
> a ULA destination address that is not local YOU DO NOT WANT TO USE
> IT by default when you have another choice.

Not true if you have a VPN link to a business partner and you want
your traffic to that partner to use the ULA, which is routed via
the VPN, rather than a GUA that is routed via the Internet.

Not true if an enterprise uses multiple ULA prefixes internally
for some reason.

These cases will need explicit policy table entries if the default
is de-pref as you suggest.

    Brian
> 
> What you do want is for a interface when it learns a ULA address
> to add the corresponding /48 prefix with a given precedence and a
> unique label to the table if the prefix does not exist.  And
> appropriate cleaning be done when no more interfaces exist in the
> /48.  This may require a manual tag on table entries.
> 
> Mark
> 
>>   more /etc/ip6addrctl.conf 
> #Prefix                          Prec Label     
> ::1/128                           50     0
> ::/0                              40     1     
> 2002::/16                         30     2        
> ::/96                             20     3        
> ::ffff:0.0.0.0/96                 35     4        
> fd92:7065:b8e::/48                45     5 
> fc00::/7                          5      6
>> ifconfig nfe0 inet6
> nfe0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
> 	options=82008<VLAN_MTU,WOL_MAGIC,LINKSTATE>
> 	inet6 fe80::218:f3ff:feba:9a37%nfe0 prefixlen 64 scopeid 0x5 
> 	inet6 fd92:7065:b8e:0:218:f3ff:feba:9a37 prefixlen 64 autoconf 
> 	inet6 2001:470:1f00:820:218:f3ff:feba:9a37 prefixlen 64 autoconf