Re: [v6ops] Thoughts about wider operational input

Mark Andrews <marka@isc.org> Wed, 30 March 2022 23:45 UTC

Return-Path: <marka@isc.org>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 93FDB3A11DB for <v6ops@ietfa.amsl.com>; Wed, 30 Mar 2022 16:45:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b=FUjGmF5d; dkim=pass (1024-bit key) header.d=isc.org header.b=foU5rGv5
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uDeSu0Wlo6Ow for <v6ops@ietfa.amsl.com>; Wed, 30 Mar 2022 16:45:38 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7CF53A11CB for <v6ops@ietf.org>; Wed, 30 Mar 2022 16:45:38 -0700 (PDT)
Received: from zimbrang.isc.org (zimbrang.isc.org [149.20.1.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id 6934E3AB00B; Wed, 30 Mar 2022 23:45:37 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 mx.pao1.isc.org 6934E3AB00B
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1648683937; bh=d8gf1NXv600cMpT1bwQrtBphOsGmbRnUMR19S925Q0U=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=FUjGmF5dZ6p1TQjb2+kpXYdOpuno34y+vK/oa1LM988zwu6nhZd5z1YvODmdSG7VN fTt/OgUfLI6vpFH3fn8N704wTHcvOBu30ZJtl8FoVwCcunoAiFn0ipiMQ8BeJQ94vS DJ24N8Y6SjUbSoe5/3ltUfJSH9aYolWcAhk388LQ=
Received: from zimbrang.isc.org (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTPS id 9774AECAC7A; Wed, 30 Mar 2022 23:44:29 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTP id 68D01ECAC7C; Wed, 30 Mar 2022 23:44:29 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbrang.isc.org 68D01ECAC7C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1648683869; bh=toI1PQWM9jrjJ0WaB/XUswJU56dymX52w10hX5QE7fA=; h=Mime-Version:From:Date:Message-Id:To; b=foU5rGv54jxvPc13USeg0tlDvvTh59MlHKMOufJyuf8xeyck1M6aPAnLEw3N6eaLr DrNd1BBkczvHmsIa6Z0kIJOEcJJVUUNEzA55UgPtxaeRXTnm7iIHv0AnZHnzgeiY5e gDsgqQ4lebyeq5dK8h/mXq61YPdWZgEWlsmnrJ+0=
Received: from zimbrang.isc.org ([127.0.0.1]) by localhost (zimbrang.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id IM-BY9_YP83N; Wed, 30 Mar 2022 23:44:29 +0000 (UTC)
Received: from smtpclient.apple (n114-74-26-107.bla4.nsw.optusnet.com.au [114.74.26.107]) by zimbrang.isc.org (Postfix) with ESMTPSA id 5F405ECAC7A; Wed, 30 Mar 2022 23:44:28 +0000 (UTC)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <62447DCB.1010206@jmaimon.com>
Date: Thu, 31 Mar 2022 10:45:33 +1100
Cc: JORDI PALET MARTINEZ <jordi.palet=40consulintel.es@dmarc.ietf.org>, v6ops list <v6ops@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <F04A9339-1C9F-40AA-8FD3-646106F71D5F@isc.org>
References: <52661a3d-75dc-111a-3f23-09b10d7cb8d4@gmail.com> <A72CDDDB-CDCE-4EAF-B95E-997C764DB2C4@gmail.com> <9175dc32-45c1-e948-c20a-3bcc958b77b9@gmail.com> <YjmJQMNgnJoSInUw@Space.Net> <D75EF08F-6A41-41B2-AFB2-649CBCC1D83E@consulintel.es> <CAPt1N1nRnYUFA=yyJHx6t52yqWbmcd2Tf1H8gQuCZBd3Q3VqJw@mail.gmail.com> <7F4AEB43-4B24-4A21-AE9D-3EB512B98C46@consulintel.es> <8fac4314b8244ba6b33eea68694296d0@huawei.com> <9A13E47B-75D0-443F-9EE9-D2917ACB2D0F@consulintel.es> <CAO42Z2xUG+BXj+VQpajed9aGjH+q-HR7RX7C-T4DsTbouz7xWQ@mail.gmail.com> <F6A90BBF-7F44-403E-960A-8F756353B562@chinatelecom.cn> <B49417F7-3EFB-4A4D-9D1A-0D21574EA4F2@consulintel.es> <44B01ACA-3D5C-4618-B608-3B3479D29875@consulintel.es> <62447DCB.1010206@jmaimon.com>
To: Joe Maimon <jmaimon@jmaimon.com>
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/UBImnxrxVSTdinDqmVGQxtB3LXE>
Subject: Re: [v6ops] Thoughts about wider operational input
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Mar 2022 23:45:45 -0000


> On 31 Mar 2022, at 02:56, Joe Maimon <jmaimon@jmaimon.com> wrote:
> 
> 
> 
> JORDI PALET MARTINEZ wrote:
>> 
>> To demonstrate how NAT is not security, you just need to enable Teredo or any other UDP tunneling traversing the NAT, so the security guys can see that without any special config in the NAT, you can dig a whole on it (Teredo Navalis = Shipworm).
>> 
>> Regards,
>> 
>> Jordi
>> 
>> @jordipalet
>> 
> 
> And then you need to demonstrate how the equivalent would not happen on IPv6.

The fix is the same in both protocols.  Install a FIREWALL and properly configure it to block port 3544.
NAT is not and never has been a FIREWALL.

A flat screw drive and a flat chisel can both be used to remove screws or dig out wood.  They both work
well at what they are designed to do and not for which they are not designed to do.

> Joe
> 
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org