nanog mailing list archives

Re: NDP DoS attack


From: Florian Weimer <fw () deneb enyo de>
Date: Sun, 17 Jul 2011 11:15:25 +0200

* Jared Mauch:

Solving a local attack is something I consider different in scope
than the current draft being discussed in 6man, v6ops, ipv6@ etc...

That's not going to happen because it's a layering violation between
the IETF and IEEE.  It has not been solved during thirty years of IPv4
over Ethernet.  Why would be IPv6 be different?

In practice, the IPv4 vs IPv6 difference is that some vendors provide
DHCP snooping, private VLANs and unicast flood protection in IPv4
land, which seems to provide a scalable way to build Ethernet networks
with address validation---but there is nothing comparable for IPv6
right now, from any vendor.

_____
NANOG mailing list
NANOG () nanog org
https://mailman.nanog.org/mailman/listinfo/nanog


Current thread: