Re: [v6ops] Thoughts about wider operational input

Brian E Carpenter <brian.e.carpenter@gmail.com> Wed, 30 March 2022 21:15 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D42E53A10AA for <v6ops@ietfa.amsl.com>; Wed, 30 Mar 2022 14:15:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H-M5hbA_gi2s for <v6ops@ietfa.amsl.com>; Wed, 30 Mar 2022 14:15:07 -0700 (PDT)
Received: from mail-pf1-x42c.google.com (mail-pf1-x42c.google.com [IPv6:2607:f8b0:4864:20::42c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 502673A0E8F for <v6ops@ietf.org>; Wed, 30 Mar 2022 14:15:07 -0700 (PDT)
Received: by mail-pf1-x42c.google.com with SMTP id u22so19998916pfg.6 for <v6ops@ietf.org>; Wed, 30 Mar 2022 14:15:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language:content-transfer-encoding; bh=uTLPLVed8dkBixal0CtqTLHjkpe4BED+hJbEGG1YhHA=; b=bFSvHzIeQGpVN5HFTH1vsymwDpw8K9gJ5/igDuryX6GWJkg5B5w+aXaa1yVA0tSvKE w9+9684EtUSoMLCezUOGqy1cJFyGTd66ZYYK0Ks4B3c4qfSN+LPmOlrEJuNP48B3KO/E 5OiDw8anUfYF6Fs+vSHc3FnrKsVwrlqT5JPhbT1CejqTSGaisu9RPB7OFGl9eKLsr0Nz LW/HYKQOersZsUxucXBNHHMx3Rdm3LMbv0XEW1MnAtwAfZlsb/z26KinGjQC2lZplzOA JPbGLw+J05pxdFTMLzgyncv6Y+BZqP7J1Qdhk7IU9HV4gaaz1Wj/UJSjCwzJgkk/h1oe nsRA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=uTLPLVed8dkBixal0CtqTLHjkpe4BED+hJbEGG1YhHA=; b=tdNX8CUyYvS+fGe/brsZjEfrfwcC1/6UO5tufXgOQY1OeCXqEb+oPXzOkCST7EjFSX JetdUQ1JHHgLdwdFVOmvx7SPV4dUrimv34/ZtJcON9cqhdk3CYERA4ZZh37s787nqtv7 ZSkjZ69gGJn+Djd/2Qz2SWFqPqjGS2k3hE4cGKEjPaQ11OhPcW034n5xUXuJURA/oxQb FLbgAwVtjpIbg2OpXZSGUiz1sOJ51NGZdwcwDGWDicCD+Pt3/BZxenq3Fmj+7ulUq87p lPOx3IR+ltvVAffNTCIinV9ugogbKT275iVYqMTw5P1STOYOBwgtYEPiW8Bkvv2ZL35W 2y+w==
X-Gm-Message-State: AOAM531eHc5dbO0Kii88oPexVIM7dsyPkVGSFF4lraazh9qDFy7naxYd tl6i2WUyspcary3PEae4CORQwnmcwwcVmA==
X-Google-Smtp-Source: ABdhPJwTxlwRkyrKYQRz/M2ilrdASqH/3wN6xyk5xLzVGfmgfu40TQX0QusoSUaSZrHEiJebcUzbSg==
X-Received: by 2002:a63:f40e:0:b0:380:6a04:4335 with SMTP id g14-20020a63f40e000000b003806a044335mr7847028pgi.523.1648674906044; Wed, 30 Mar 2022 14:15:06 -0700 (PDT)
Received: from ?IPv6:2406:e003:1005:b501:80b2:5c79:2266:e431? ([2406:e003:1005:b501:80b2:5c79:2266:e431]) by smtp.gmail.com with ESMTPSA id z20-20020aa78894000000b004fb11506899sm20458525pfe.139.2022.03.30.14.15.04 for <v6ops@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 30 Mar 2022 14:15:05 -0700 (PDT)
To: v6ops@ietf.org
References: <52661a3d-75dc-111a-3f23-09b10d7cb8d4@gmail.com> <A72CDDDB-CDCE-4EAF-B95E-997C764DB2C4@gmail.com> <9175dc32-45c1-e948-c20a-3bcc958b77b9@gmail.com> <YjmJQMNgnJoSInUw@Space.Net> <D75EF08F-6A41-41B2-AFB2-649CBCC1D83E@consulintel.es> <CAPt1N1nRnYUFA=yyJHx6t52yqWbmcd2Tf1H8gQuCZBd3Q3VqJw@mail.gmail.com> <7F4AEB43-4B24-4A21-AE9D-3EB512B98C46@consulintel.es> <8fac4314b8244ba6b33eea68694296d0@huawei.com> <9A13E47B-75D0-443F-9EE9-D2917ACB2D0F@consulintel.es> <CAO42Z2xUG+BXj+VQpajed9aGjH+q-HR7RX7C-T4DsTbouz7xWQ@mail.gmail.com> <F6A90BBF-7F44-403E-960A-8F756353B562@chinatelecom.cn> <B49417F7-3EFB-4A4D-9D1A-0D21574EA4F2@consulintel.es> <44B01ACA-3D5C-4618-B608-3B3479D29875@consulintel.es> <62447DCB.1010206@jmaimon.com> <7228D9A7-54A8-4BAE-9299-204C049F600B@consulintel.es>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Message-ID: <de1d6cf9-ce16-4347-dfdf-17a427468199@gmail.com>
Date: Thu, 31 Mar 2022 10:15:02 +1300
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.10.0
MIME-Version: 1.0
In-Reply-To: <7228D9A7-54A8-4BAE-9299-204C049F600B@consulintel.es>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/itUw596E2z-n44vCiY8Qf0vMXnY>
Subject: Re: [v6ops] Thoughts about wider operational input
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Mar 2022 21:15:12 -0000

Jordi,

As we all know, home gateways that support IPv6 are shipped with a quite adequate default firewall configuration. Is there a good specification for a default firewall configuration for an SME CE router?

Probably this isn't realistic for large enterprises?

    Brian
On 31-Mar-22 07:27, JORDI PALET MARTINEZ wrote:
> Because if you don't have NAT, you are forced to properly configure a firewall.
> 
> With a NAT, many don't even have a firewall or is not sufficiently well 
configured.
> 
> Regards,
> Jordi
> @jordipalet
>   
>   
> 
> El 30/3/22, 17:58, "v6ops en nombre de Joe Maimon" <v6ops-bounces@ietf.org en nombre de jmaimon@jmaimon.com> escribió:
> 
> 
> 
>      JORDI PALET MARTINEZ wrote:
>      >
>      > To demonstrate how NAT is not security, you just need to enable Teredo
>      > or any other UDP tunneling traversing the NAT, so the security guys
>      > can see that without any special config in the NAT, you can dig a
>      > whole on it (Teredo Navalis = Shipworm).
>      >
>      > Regards,
>      >
>      > Jordi
>      >
>      > @jordipalet
>      >
> 
>      And then you need to demonstrate how the equivalent would not happen on
>      IPv6.
> 
>      Joe
> 
>      _______________________________________________
>      v6ops mailing list
>      v6ops@ietf.org
>      https://www.ietf.org/mailman/listinfo/v6ops
> 
> 
> 
> **********************************************
> IPv4 is over
> Are you ready for the new Internet ?
> http://www.theipv6company.com
> The IPv6 Company
> 
> This electronic message contains information which may be privileged or 
confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is 
strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete 
it.
> 
> 
> 
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops
>