Re: [v6ops] Please review the No IPv4 draft

Nick Hilliard <nick@foobar.org> Mon, 28 April 2014 22:27 UTC

Return-Path: <nick@foobar.org>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B56F81A8832 for <v6ops@ietfa.amsl.com>; Mon, 28 Apr 2014 15:27:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r_CLaNvqbFGS for <v6ops@ietfa.amsl.com>; Mon, 28 Apr 2014 15:27:09 -0700 (PDT)
Received: from mail.netability.ie (mail.netability.ie [IPv6:2a03:8900:0:100::5]) by ietfa.amsl.com (Postfix) with ESMTP id 41A7A1A6FB8 for <v6ops@ietf.org>; Mon, 28 Apr 2014 15:27:08 -0700 (PDT)
X-Envelope-To: v6ops@ietf.org
Received: from [10.230.100.84] (xe-0-0-2.transit07.phb1.foobar.org [87.192.56.84]) (authenticated bits=0) by mail.netability.ie (8.14.8/8.14.5) with ESMTP id s3SMR5Ru062447 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Mon, 28 Apr 2014 23:27:07 +0100 (IST) (envelope-from nick@foobar.org)
X-Authentication-Warning: cheesecake.netability.ie: Host xe-0-0-2.transit07.phb1.foobar.org [87.192.56.84] claimed to be [10.230.100.84]
References: <9B4139A3-77F7-4109-93AD-A822395E5007@nominum.com> <m24n1l8i1a.wl%Niall.oReilly@ucd.ie> <3BA3E5A3-4385-43CE-B73F-A0686AA31B4E@nominum.com> <m238gxpgrt.wl%Niall.oReilly@ucd.ie> <73221D87-5F50-4689-AA42-553AF757ABF5@nominum.com> <m2mwf59uht.wl%Niall.oReilly@ucd.ie> <7310412C-64E9-4A11-9812-92A969082131@nominum.com> <20140428190804.GK43641@Space.Net> <446A720E-1128-4FFF-BB3B-780EACA9610B@nominum.com> <535EBC20.10900@foobar.org> <20140428213045.GL511@havarti.local> <19B5B5AB-FF86-408B-8E73-D5350853965B@foobar.org> <A7C9EEC2-2173-424F-9B91-30C775D07AA0@nominum.com>
Mime-Version: 1.0 (1.0)
In-Reply-To: <A7C9EEC2-2173-424F-9B91-30C775D07AA0@nominum.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Message-Id: <24256227-1B50-4B2F-9C2D-1ECA5C51FCEF@foobar.org>
X-Mailer: iPhone Mail (11D201)
From: Nick Hilliard <nick@foobar.org>
Date: Mon, 28 Apr 2014 23:27:06 +0100
To: Ted Lemon <ted.lemon@nominum.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/v6ops/dlCdlS0gb9kJA8GOhRJvB-boRgA
Cc: "v6ops@ietf.org WG" <v6ops@ietf.org>
Subject: Re: [v6ops] Please review the No IPv4 draft
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Apr 2014 22:27:11 -0000

On 28 Apr 2014, at 23:03, Ted Lemon <ted.lemon@nominum.com> wrote:
> Yes, but the nexus 1000 has a firewall.

I think you're getting mixed up here. The nexus 1000v is a virtual switch and the asa1000v is the virtual firewall. 

This isn't a firewalling issue because FWs act at layer 3 and ra guard / dhcpv6 guard act at l2.  If you're referring to vsg, that's zone based protection which is a different kettle of fish.

>  Are you telling me that there's no way to configure the firewall to block rogue RAs?

There is currently no way to block rogue RAs or rogue dhcpv6 pkts at layer 2 on VMware esxi, either with the Cisco nexus1000v soft-switch or the native soft-switch.

Nick