Re: [v6ops] Please review the No IPv4 draft

Nick Hilliard <nick@foobar.org> Mon, 28 April 2014 20:38 UTC

Return-Path: <nick@foobar.org>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0BEC41A6FB9 for <v6ops@ietfa.amsl.com>; Mon, 28 Apr 2014 13:38:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DH9Hmf5gd4oU for <v6ops@ietfa.amsl.com>; Mon, 28 Apr 2014 13:37:55 -0700 (PDT)
Received: from mail.netability.ie (mail.netability.ie [IPv6:2a03:8900:0:100::5]) by ietfa.amsl.com (Postfix) with ESMTP id AD7301A6FB7 for <v6ops@ietf.org>; Mon, 28 Apr 2014 13:37:54 -0700 (PDT)
X-Envelope-To: v6ops@ietf.org
Received: from cupcake.foobar.org ([IPv6:2001:4d68:2002:100::110]) (authenticated bits=0) by mail.netability.ie (8.14.8/8.14.5) with ESMTP id s3SKbqaq061551 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO); Mon, 28 Apr 2014 21:37:52 +0100 (IST) (envelope-from nick@foobar.org)
X-Authentication-Warning: cheesecake.netability.ie: Host [IPv6:2001:4d68:2002:100::110] claimed to be cupcake.foobar.org
Message-ID: <535EBC20.10900@foobar.org>
Date: Mon, 28 Apr 2014 21:37:52 +0100
From: Nick Hilliard <nick@foobar.org>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: Ted Lemon <ted.lemon@nominum.com>
References: <m1WcbPl-0000COC@stereo.hq.phicoh.net> <118D079B-FC99-4606-B289-4201137A5815@nominum.com> <CAKD1Yr2f-RH4i3creThGGSx2YxdUTbEW1ACW_0TXz857Kbmv7w@mail.gmail.com> <9B4139A3-77F7-4109-93AD-A822395E5007@nominum.com> <m24n1l8i1a.wl%Niall.oReilly@ucd.ie> <3BA3E5A3-4385-43CE-B73F-A0686AA31B4E@nominum.com> <m238gxpgrt.wl%Niall.oReilly@ucd.ie> <73221D87-5F50-4689-AA42-553AF757ABF5@nominum.com> <m2mwf59uht.wl%Niall.oReilly@ucd.ie> <7310412C-64E9-4A11-9812-92A969082131@nominum.com> <20140428190804.GK43641@Space.Net> <446A720E-1128-4FFF-BB3B-780EACA9610B@nominum.com>
In-Reply-To: <446A720E-1128-4FFF-BB3B-780EACA9610B@nominum.com>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/v6ops/ZKBnh_B4riQFKx7rdCi4-fyT67I
Cc: "v6ops@ietf.org WG" <v6ops@ietf.org>
Subject: Re: [v6ops] Please review the No IPv4 draft
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Apr 2014 20:38:02 -0000

On 28/04/2014 20:53, Ted Lemon wrote:
> Seems like you could insist.   How old is the newest non-IPv6-capable
> equipment?

Well you can insist, yes, but it takes time and patience, during which your
network can be vulnerable to problems.

There's a slightly old list for RA guard support here:

> https://www.ernw.de/download/raguard_support_05022013.pdf

You can see that RA Guard (+ dhcpv6 guard) is absent on the entire Cisco
Nexus line.  This can be worked around to some degree for physical
hardware, but not for virtualised infrastructure, where the situation is
pretty grim at least for vmware based hypervisors.

I haven't found a similar list for DHCPv6 guard, but from previous
investigation, support was even less well developed compared to RA guard
due to the complexities involved if the support involves anything other
than a simple tcp/udp port block.

Nick