nanog mailing list archives
Re: Only 5x IPv4 /8 remaining at IANA
From: Henning Brauer <hb-nanog () bsws de>
Date: Mon, 18 Oct 2010 20:19:04 +0200
* Owen DeLong <owen () delong com> [2010-10-18 18:29]:
The good news is that stateful inspection doesn't go away in IPv6.
that is right.
It works just fine. All that goes away is the header mangling.
that is partially true. it can work just fine, but all the bloat in v6 makes it way harder to implement the state tracking than it should be.
It's really unfortunate that most people don't understand the distinction. If they did, it would help them to realize that NAT doesn't actually do anything for security, it just helps with address conservation (although it has some limits there, as well).
right.
IPv6 with SI is no less secure than IPv4 with SI+NAT.
well, it is. the extension headers are horrible. the v4 mapping horror is an insane trap, too. link-local is the most horrid concept ever. all hail 160 bit addresses. all that leads to bugs in the implementations (while the bugs are really in the specification, I'd claim). the RH0 desaster was just the beginning. -- Henning Brauer, hb () bsws de, henning () openbsd org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting
Current thread:
- RE: Only 5x IPv4 ... WRONG! :), (continued)
- RE: Only 5x IPv4 ... WRONG! :) George Bonser (Oct 19)
- Re: Only 5x IPv4 ... WRONG! :) Owen DeLong (Oct 20)
- RE: Only 5x IPv4 ... WRONG! :) George Bonser (Oct 20)
- RE: Only 5x IPv4 ... WRONG! :) George Bonser (Oct 20)
- Re: Only 5x IPv4 ... WRONG! :) Owen DeLong (Oct 20)
- RE: Only 5x IPv4 ... WRONG! :) George Bonser (Oct 20)
- Re: Only 5x IPv4 ... WRONG! :) Ray Soucy (Oct 21)
- Re: Only 5x IPv4 ... WRONG! :) bmanning (Oct 21)
- Re: Only 5x IPv4 ... WRONG! :) Michael Dillon (Oct 21)
- Re: Only 5x IPv4 ... WRONG! :) Bryan Irvine (Oct 21)
- Re: Only 5x IPv4 /8 remaining at IANA Henning Brauer (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Seth Mattinen (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Owen DeLong (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Joel Jaeggli (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Jared Mauch (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Mark Smith (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Joel Jaeggli (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Jeffrey Lyon (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Franck Martin (Oct 18)
- Re: Only 5x IPv4 /8 remaining at IANA Jeffrey Lyon (Oct 18)