Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: nsp: ipv6

CPE firewalls

 

 

nsp ipv6 RSS feed   Index | Next | Previous | View Threaded


alan.batie at peakinternet

Sep 3, 2009, 5:53 PM

Post #1 of 2 (911 views)
Permalink
CPE firewalls

Bjørn Mork wrote:

> Right. Thanks for the idea. I do have a few places where I can push
> things like that. This is maybe something for
> http://www.ietf.org/id/draft-ietf-v6ops-ipv6-cpe-router-01.txt

After reading this draft, I sent a request to the authors to include a
firewall addition to the effect of "a CPE Router SHOULD default to
blocking incoming TCP connection requests and incoming UDP packets". In
essence, the router should provide the same basic default firewall
capability that NAT gives now.

While not full security, it at least provides network protection at the
same level users have now, and without this default state or NAT6x,
users are going to be highly vulnerable. There is a big difference
between "I forgot to configure the router" or "I configured it wrong
accidentally" and "I decided to make changes from the default and
accidentally opened a hole".


alan.batie at peakinternet

Sep 3, 2009, 5:59 PM

Post #2 of 2 (848 views)
Permalink
Re: CPE firewalls [In reply to]

Argh! I missed the link to a whole separate document on the issue,
never mind...

nsp ipv6 RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.