Re: ipset, IP6_NF_IPTABLES

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 17/05/2011 12:14, Denys Fedoryshchenko wrote:
> Especially it is a problem for source based distributions, like gentoo,


I know there was a debate about this on the gentoo-hardened list
recently, but my opinion is that one needs to start "enabling" (as in
it's installed/compiled in) IPV6 code on all systems ASAP and start
flushing out problems.  That said I think it's also fair to lock
down/disable/minimise your use of the IPV6 to whatever is appropriate to
your environment/requirements, but having the code there, compiled into
production systems and starting to test it would seem to be very prudent
right now?

Just add USE="+ipv6" to your make.conf, "emerge --newuse -uvDkp world"
and off you go...

Good luck

Ed W
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux