Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?
Hubert W <hubert.wisniewski@gmail.com> Wed, 24 April 2024 20:23 UTC
Return-Path: <hubert.wisniewski@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 231E4C14F61A; Wed, 24 Apr 2024 13:23:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 66y5sczEwKLf; Wed, 24 Apr 2024 13:23:36 -0700 (PDT)
Received: from mail-qt1-x82b.google.com (mail-qt1-x82b.google.com [IPv6:2607:f8b0:4864:20::82b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5AF47C14F5FB; Wed, 24 Apr 2024 13:23:36 -0700 (PDT)
Received: by mail-qt1-x82b.google.com with SMTP id d75a77b69052e-43a317135a5so2928381cf.0; Wed, 24 Apr 2024 13:23:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1713990215; x=1714595015; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=WF94YYCHGv2RV+/GKsPx5qPqhxOBRWnH8lQwhNMAcuA=; b=L+gs1PtybzcPm5TZEBJcO/X9w3+QfUkBs8it8/Daur0hW8dj2tUo6gP++Csz6U3mIn vECJN2TMIerA5dWaWJZqrK/CnAprW/d2ZDQx93SUaffgjIDkM4c+Eq7kjYNDwkuuABdx qElVYkfoH5aXUp9EPgBjyvHyr5KB74wqQBoGXKN4FwiKQv3mSN6GcJNoerIyuxe+oTlQ TDuMf84XWzYxN9gFQyNtsNIGaWpliHNHJ5km10vG6nlQqUIs55qFc58jQJwMZCNzJ5DF bK3ELTlpQmQLX8biyAerQUTgn8nt4dpJlJWtnjwFo25vI88Beka1I5Q3vrI6OX87/2bh CAbw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713990215; x=1714595015; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=WF94YYCHGv2RV+/GKsPx5qPqhxOBRWnH8lQwhNMAcuA=; b=vs0BennJzwcrCPWNFhUuwSR1UoNHxaZuDSn2ap1jJTRrj0aaefLN3AxEhVmdw7/eGY EefrXHLpZatQ0kcq4QQ2ZyLpLCHJ4eVgNeRhd/omrYpsnPjp+dHWMmyeNEF3J7oUUUSe qwRLdJxI7XtKkqdsZ7DVTetgId45bCk2995L0u3TNsqnERfUV97L3NzfQu56/ebcH1mu 6ifztNtlHq+9HCewBqnFYidIaZqt1hLJtYF0UV2K0Vi/2JwEfsUmkm/lHMUhfliApnvN PEy+eSmVZ6hrrhsMn4E5ik9kwmCovuWAjtfrNr1HZVLjq5x/JcRwISF323Y8SgBLKR18 UYsw==
X-Forwarded-Encrypted: i=1; AJvYcCVvob50G3/IfkyYC8LIBzdF7A5aA8ZvgLmEQLF+/bX1RqBuxycrLITASWIHAGufTkoO1R3MyymeahguILk=
X-Gm-Message-State: AOJu0YzBmBiJGNXRDOYDAQKVYWJcIx1yi7kI1kAXCdHvKRAkHHU3NXOi n/5jZ+hKzYMbgumqRL+1LHPmiFQUH00ZzP+TRonVjIn1Hj1Efnpn0N6JQdznVWVrJ2KpfE/DKbN SG/k6qoov0wOn4jyr66SopusinhYb5YhOx+8=
X-Google-Smtp-Source: AGHT+IG4OwurAeiRQixVcdcY9oPMGE6I3NKFXc2sETqJjFWfGihtQQi/RfKpuS6LKfEjFhQTsWiXuRRi5AIMl3Z9Eg4=
X-Received: by 2002:a05:622a:87:b0:439:75a5:ae54 with SMTP id o7-20020a05622a008700b0043975a5ae54mr1528085qtw.11.1713990214945; Wed, 24 Apr 2024 13:23:34 -0700 (PDT)
MIME-Version: 1.0
References: <CAMkkUf3UqjJbuBQwvaOAsV=4VwPYBCUTBNLfUB2ZF4gAv4CHnQ@mail.gmail.com> <D4424AFD-CE28-46C8-808E-A41979973DA4@isc.org>
In-Reply-To: <D4424AFD-CE28-46C8-808E-A41979973DA4@isc.org>
From: Hubert W <hubert.wisniewski@gmail.com>
Date: Wed, 24 Apr 2024 22:23:23 +0200
Message-ID: <CAMkkUf1brxg1DhPiv-93PtN1pOyGsGhLopGbxTW6jgz+c92wTA@mail.gmail.com>
To: Mark Andrews <marka@isc.org>
Cc: 6man <ipv6@ietf.org>, 6lo@ietf.org
Content-Type: multipart/alternative; boundary="000000000000e9143d0616dd713a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/r1OHXkjUcpxhstCwWP_8TzHWnTs>
Subject: Re: [IPv6] Can We Turn the Global Network into a Firewall Protecting All End Users?
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Apr 2024 20:23:37 -0000
On Wed, Apr 24, 2024, 07:46 Mark Andrews <marka@isc.org> wrote: > > > > On 23 Apr 2024, at 16:51, Hubert W <hubert.wisniewski@gmail.com> wrote: > > > > Dear WG, > > > > > > I woke up with one idea and I would like to challenge it. > > In IPv6, every device receives a routable address. To protect endpoints > effectively, we require firewalls to filter unwanted traffic. > > Apart from packet volume this is a false assertion. No device should > require a firewall. > > > But what if we could stop such traffic at the source? Could this > approach convince more people toward adopting IPv6? > > > > According to RFC 7381: “In a /48 assignment, typical for a site, there > are then still 65,535 /64 blocks.” and “All user access networks should be > a /64.” > > /64 is typical not required. > > > Can we use then bit 63 to convey a message: “I don’t want any incoming > traffic initiated towards me!!!”? Of course a response would be accepted. > > > > We could divide the /64 allocations into two groups: one for servers, > and these accept incoming traffic (bit 63 = 0): > > > > for example 2001:0db8:0000:0000::/64 > > > > And the second group: endpoints, these never accept incoming traffic > (bit 63 = 1): > > > > for example 2001:0db8:0000:0001::/64 > > > > We only need all systems to understand the message. If a router or > firewall sees such a packet, then drops it. > > Every TCP packet with flag SYN, where destination address (IPv6) has bit > 63 equal 1, must be dropped. > > All the world is not TCP. Additionally for TCP the filtering device would > need to track state and that implies symmetric routing. > > > Would it be theoretically possible? > > No. > > > Best regards > > > > Hubert Wisniewski > > > > -------------------------------------------------------------------- > > IETF IPv6 working group mailing list > > ipv6@ietf.org > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > > -------------------------------------------------------------------- > > -- > Mark Andrews, ISC > 1 Seymour St., Dundas Valley, NSW 2117, Australia > PHONE: +61 2 9871 4742 INTERNET: marka@isc.org I think there would be no issue with asymmetric traffic if we only check SYN flag, but I understand that is not a good idea. Thank you for your opinion. Hubert Wisniewski
- [IPv6] Can We Turn the Global Network into a Fire… Hubert W
- Re: [IPv6] Can We Turn the Global Network into a … Mark Andrews
- Re: [IPv6] Can We Turn the Global Network into a … Hubert W
- Re: [IPv6] Can We Turn the Global Network into a … Jared Mauch
- Re: [IPv6] Can We Turn the Global Network into a … Ted Lemon