Re: Node Requirements: Elevating DHCPv6 from MAY to SHOULD
Philip Homburg <pch-6man@u-1.phicoh.com> Tue, 31 May 2011 11:39 UTC
Return-Path: <pch-b2B3A6689@u-1.phicoh.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 450BBE06B9 for <ipv6@ietfa.amsl.com>; Tue, 31 May 2011 04:39:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.471
X-Spam-Level:
X-Spam-Status: No, score=-8.471 tagged_above=-999 required=5 tests=[AWL=0.128, BAYES_00=-2.599, GB_I_LETTER=-2, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VZyxUU1EmzpK for <ipv6@ietfa.amsl.com>; Tue, 31 May 2011 04:39:58 -0700 (PDT)
Received: from stereo.hq.phicoh.net (stereo.hq.phicoh.net [130.37.15.35]) by ietfa.amsl.com (Postfix) with ESMTP id DE73AE076F for <ipv6@ietf.org>; Tue, 31 May 2011 04:39:57 -0700 (PDT)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (Smail #55) id m1QRNIi-0001gzC; Tue, 31 May 2011 13:39:56 +0200
Message-Id: <m1QRNIi-0001gzC@stereo.hq.phicoh.net>
To: Mikael Abrahamsson <swmike@swm.pp.se>
Subject: Re: Node Requirements: Elevating DHCPv6 from MAY to SHOULD
From: Philip Homburg <pch-6man@u-1.phicoh.com>
Sender: pch-b2B3A6689@u-1.phicoh.com
References: <C9F53B85.11BE93%john_brzozowski@cable.comcast.com> <201105232010.p4NKAV9X012654@cichlid.raleigh.ibm.com> <53E999C4-E50D-49C9-9B02-8AD7B5641905@gmail.com> <BANLkTinByCkcvd6=wLE6=9h1xLX16AhPVQ@mail.gmail.com> <201105232111.p4NLBScJ013180@cichlid.raleigh.ibm.com> <20110524072631.737ee12c@opy.nosense.org> <3044C560-F46C-477A-BD87-DF252F689FAB@equinux.de> <m1QR93e-0001IXC@stereo.hq.phicoh.net> <62797F6E-20DF-4038-A29A-1FDB0A94C678@equinux.de> <m1QRL7I-0001h2C@stereo.hq.phicoh.net> <alpine.DEB.2.00.1105311225350.13754@uplift.swm.pp.se> <m1QRMNF-0001ipC@stereo.hq.phicoh.net> <alpine.DEB.2.00.1105311247370.13754@uplift.swm.pp.se>
In-reply-to: Your message of "Tue, 31 May 2011 13:06:20 +0200 (CEST) ." <alpine.DEB.2.00.1105311247370.13754@uplift.swm.pp.se>
Date: Tue, 31 May 2011 13:39:55 +0200
Cc: "ipv6@ietf.org" <ipv6@ietf.org>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 May 2011 11:39:59 -0000
In your letter dated Tue, 31 May 2011 13:06:20 +0200 (CEST) you wrote: >Absolutely, but if there is another way than to announce the on-link >prefix than might make hosts communicate directly to each other on a >subnet, that's news to me and I find this extremely interesting from a >security standpoint. > >For me, if I have: > >R1 X::1/64 >H2 X::2/128 >H3 X::3/128 > >R1 doesn't announce any on-link prefix, so H2 and H3 use R1 to communicate >between each other (they just have their own /128 in their routing table >and default route pointing to R1 LL address learnt via RA). > >Now, what I interpreted you saying is that R1 can tell H2 that H3 is >on-link by means of an ICMP redirect. This has security (and functional) >implications in that any L2 network they might have that disallows H2 and >H3 to communicate between each other even though they're in the same vlan, >will make this completely stop working if R1 doesn't have a knob to >disallow it from sending redirects that might indicate that H2 and H3 is >on the same L2 domain (on-link). RFC-4861 (Neighbor Discovery for IP version 6 (IPv6)): "8.3. Host Specification [...] "If the Target and Destination Addresses are the same, the host MUST treat the "Target as on-link. I have no idea why you want hosts on the same vlan and then use L2 filtering to prevent them from communicating directly. But yes, if the router would then start sending redirects, it would create a mess.
- RE: Node Requirements: Elevating DHCPv6 from MAY … Templin, Fred L
- Re: Node Requirements: Elevating DHCPv6 from MAY … Bob Hinden
- Node Requirements: Elevating DHCPv6 from MAY to S… Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Ralph Droms
- Re: Node Requirements: Elevating DHCPv6 from MAY … Tim Chown
- Re: Node Requirements: Elevating DHCPv6 from MAY … Cameron Byrne
- Re: Node Requirements: Elevating DHCPv6 from MAY … Scott Brim
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- RE: Node Requirements: Elevating DHCPv6 from MAY … john.loughney
- Re: Node Requirements: Elevating DHCPv6 from MAY … Ralph Droms
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Ralph Droms
- Re: Node Requirements: Elevating DHCPv6 from MAY … Timothy E. Enos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Bob Hinden
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mikael Abrahamsson
- RE: Node Requirements: Elevating DHCPv6 from MAY … john.loughney
- RE: Node Requirements: Elevating DHCPv6 from MAY … john.loughney
- RE: Node Requirements: Elevating DHCPv6 from MAY … john.loughney
- RE: Node Requirements: Elevating DHCPv6 from MAY … Basavaraj.Patil
- Re: Node Requirements: Elevating DHCPv6 from MAY … Christopher Morrow
- Re: Node Requirements: Elevating DHCPv6 from MAY … Wes Beebee
- Re: Node Requirements: Elevating DHCPv6 from MAY … Alexandru Petrescu
- Re: Node Requirements: Elevating DHCPv6 from MAY … Alexandru Petrescu
- Re: Node Requirements: Elevating DHCPv6 from MAY … james woodyatt
- Re: Node Requirements: Elevating DHCPv6 from MAY … Suresh Krishnan
- Re: Node Requirements: Elevating DHCPv6 from MAY … Cameron Byrne
- Re: Node Requirements: Elevating DHCPv6 from MAY … Randy Bush
- Re: Node Requirements: Elevating DHCPv6 from MAY … Wes Beebee
- Re: Node Requirements: Elevating DHCPv6 from MAY … james woodyatt
- Re: Node Requirements: Elevating DHCPv6 from MAY … Basavaraj.Patil
- Re: Node Requirements: Elevating DHCPv6 from MAY … Behcet Sarikaya
- Re: Node Requirements: Elevating DHCPv6 from MAY … Ed Jankiewicz
- RE: Node Requirements: Elevating DHCPv6 from MAY … Manfredi, Albert E
- RE: Node Requirements: Elevating DHCPv6 from MAY … Tony Hain
- Re: Node Requirements: Elevating DHCPv6 from MAY … sthaug
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brian Haberman
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brzozowski, John
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brzozowski, John
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brzozowski, John
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brzozowski, John
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brzozowski, John
- Re: Node Requirements: Elevating DHCPv6 from MAY … Timothy E. Enos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brian E Carpenter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Seiichi Kawamura
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Ralph Droms
- Re: Node Requirements: Elevating DHCPv6 from MAY … Christopher Morrow
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brian E Carpenter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mark Smith
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brian E Carpenter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mark Smith
- RE: Node Requirements: Elevating DHCPv6 from MAY … Manfredi, Albert E
- Re: Node Requirements: Elevating DHCPv6 from MAY … Christopher Morrow
- Re: Node Requirements: Elevating DHCPv6 from MAY … Christopher Morrow
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Christopher Morrow
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Carsten Bormann
- Re: Node Requirements: Elevating DHCPv6 from MAY … james woodyatt
- RE: Node Requirements: Elevating DHCPv6 from MAY … Templin, Fred L
- RE: Node Requirements: Elevating DHCPv6 from MAY … Christopher Palmer
- RE: Node Requirements: Elevating DHCPv6 from MAY … john.loughney
- Re: Node Requirements: Elevating DHCPv6 from MAY … Thomas Narten
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mark Smith
- Re: Node Requirements: Elevating DHCPv6 from MAY … Brian E Carpenter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mark Smith
- RE: Node Requirements: Elevating DHCPv6 from MAY … Templin, Fred L
- Re: Node Requirements: Elevating DHCPv6 from MAY … Doug Barton
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mark Smith
- Re: Node Requirements: Elevating DHCPv6 from MAY … Tim Chown
- Re: Node Requirements: Elevating DHCPv6 from MAY … RJ Atkinson
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Ray Hunter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Multiple addresses [was Node Requirements: Elevat… Brian E Carpenter
- Re: Multiple addresses [was Node Requirements: El… Fred Baker
- Re: Multiple addresses [was Node Requirements: El… Ray Hunter
- Re: Multiple addresses [was Node Requirements: El… Fred Baker
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mikael Abrahamsson
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mikael Abrahamsson
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Markus Hanauska
- Re: Multiple addresses [was Node Requirements: El… Brian E Carpenter
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mikael Abrahamsson
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Multiple addresses [was Node Requirements: El… Tim Chown
- Re: Multiple addresses [was Node Requirements: El… Ralph Droms
- Re: Node Requirements: Elevating DHCPv6 from MAY … Markus Hanauska
- Re: Node Requirements: Elevating DHCPv6 from MAY … Mohacsi Janos
- Re: Node Requirements: Elevating DHCPv6 from MAY … Philip Homburg
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Mark Smith
- Re: [ipv6] Node Requirements: Elevating DHCPv6 fr… Markus Hanauska
- Re: Multiple addresses [was Node Requirements: El… james woodyatt
- Re: Multiple addresses [was Node Requirements: El… Ray Hunter
- Re: Multiple addresses [was Node Requirements: El… Ray Hunter
- Re: Multiple addresses [was Node Requirements: El… Mark Smith
- Re: Multiple addresses [was Node Requirements: El… Ralph Droms
- Re: Multiple addresses [was Node Requirements: El… Thomas Narten
- Re: Multiple addresses [was Node Requirements: El… Ralph Droms