Re: RFC 5006 and draft-ietf-v6ops-rogue-ra-01

Doug Barton <dougb@dougbarton.us> Thu, 10 June 2010 21:27 UTC

Return-Path: <owner-v6ops@ops.ietf.org>
X-Original-To: ietfarch-v6ops-archive@core3.amsl.com
Delivered-To: ietfarch-v6ops-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 521DE3A67AD for <ietfarch-v6ops-archive@core3.amsl.com>; Thu, 10 Jun 2010 14:27:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.364
X-Spam-Level: *
X-Spam-Status: No, score=1.364 tagged_above=-999 required=5 tests=[BAYES_20=-0.74, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bIjHSoConnpK for <ietfarch-v6ops-archive@core3.amsl.com>; Thu, 10 Jun 2010 14:27:16 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id CF3333A69AA for <v6ops-archive@lists.ietf.org>; Thu, 10 Jun 2010 14:27:15 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-v6ops@ops.ietf.org>) id 1OMpAu-000GiY-2x for v6ops-data0@psg.com; Thu, 10 Jun 2010 21:20:32 +0000
Received: from [204.14.89.4] (helo=mail2.fluidhosting.com) by psg.com with esmtp (Exim 4.71 (FreeBSD)) (envelope-from <dougb@dougbarton.us>) id 1OMpAp-000Ghv-Bi for v6ops@ops.ietf.org; Thu, 10 Jun 2010 21:20:27 +0000
Received: (qmail 19754 invoked by uid 399); 10 Jun 2010 21:20:26 -0000
Received: from localhost (HELO foreign.dougb.net) (dougb@dougbarton.us@127.0.0.1) by localhost with ESMTPAM; 10 Jun 2010 21:20:26 -0000
X-Originating-IP: 127.0.0.1
X-Sender: dougb@dougbarton.us
Message-ID: <4C115718.2090709@dougbarton.us>
Date: Thu, 10 Jun 2010 14:20:24 -0700
From: Doug Barton <dougb@dougbarton.us>
Organization: http://SupersetSolutions.com/
User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.9.1.9) Gecko/20100330 Thunderbird/3.0.4
MIME-Version: 1.0
To: Tim Chown <tjc@ecs.soton.ac.uk>
CC: v6ops@ops.ietf.org
Subject: Re: RFC 5006 and draft-ietf-v6ops-rogue-ra-01
References: <291B137B-7316-49A9-8C19-A606DCFCD019@wisc.edu> <5A07BF4F-33AB-4DB5-847B-EA1DF944C9C3@ecs.soton.ac.uk> <EMEW3|561d2bae90c9ddf8f65add274697b1eem58ESQ03tjc|ecs.soton.ac.uk|5A07BF4F-33AB-4DB5-847B-EA1DF944C9C3@ecs.soton.ac.uk> <A2C63160-0157-43E1-BCF7-2CC96B673AE7@cisco.com> <801675CF-788A-4583-9F2C-9362859DFBD6@cisco.com> <C1E1C597-CC56-48F0-AFD0-35C4496DBED5@ecs.soton.ac.uk> <EMEW3|dd6df153f280868f3fff0a6658747efcm59DXr03tjc|ecs.soton.ac.uk|C1E1C597-CC56-48F0-AFD0-35C4496DBED5@ecs.soton.ac.uk>
In-Reply-To: <EMEW3|dd6df153f280868f3fff0a6658747efcm59DXr03tjc|ecs.soton.ac.uk|C1E1C597-CC56-48F0-AFD0-35C4496DBED5@ecs.soton.ac.uk>
X-Enigmail-Version: 1.0.1
OpenPGP: id=1A1ABC84
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-v6ops@ops.ietf.org
Precedence: bulk
List-ID: <v6ops.ops.ietf.org>

On 06/10/10 05:33, Tim Chown wrote:
> The draft is focused on rogue RAs as that has been an operational
> issue for us in our dual-stack enterprise for quite some time.   The
> potential for additional forms of 'badness' to come from RA-based DNS
> configuration are worth noting, but the mitigations in general are
> the same.     There may be some additional mitigation methods
> specific to the DNS option/configuration.

Speaking as a DNS person, I can do a LOT more harm on your network if I 
can successfully direct your clients onto my malicious name server than 
rerouting their prefix information, and the name server hack will be 
much harder to detect.


Doug

-- 

	... and that's just a little bit of history repeating.
			-- Propellerheads

	Improve the effectiveness of your Internet presence with
	a domain name makeover!    http://SupersetSolutions.com/