Re: [OPSEC] Last Call: <draft-ietf-opsec-ipv6-eh-filtering-06.txt> (Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers) to Informational RFC

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Nov 27, 2018 at 2:12 AM Nick Hilliard <nick@xxxxxxxxxx> wrote:
>
> Ole Troan wrote on 27/11/2018 08:28:
> > A very unfortunate consequence of this work, is that the IETF appears
> > to send a message that routers in the Internet is now expected to
> > parse deep into packets and perform filtering actions. That’s a big
> > change of the Internet architecture, and our view of layering.
>
> quite the opposite: parsing deep inside packets has been a prerequisite
> of ipv6 EHs from the beginning

Just to be historically accurate, looking past the Hop-by-Hop Options
header (which is required to occur first) was not part of the IPv6
architecture at the beginning (RFC 2460 and predecessors).

> and a serious row-back from this position
> was previously standardised in rfc7112.

Which was acknowledgment of the reality that intermediate devices
do for many reasons inspect headers up to and including the upper
layer protocol header.

Mike Heard





[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux