Teredo source addresses from 6to4 relay

Pekka Savola pekkas at netcore.fi
Thu May 10 09:17:32 CEST 2007


I'm seeing some Teredo hosts trying to send packets to another Teredo 
hosts through our 6to4 relay, and packets getting dropped due to uRPF.

I guess some implementation doesn't properly check which packets to 
send over the 6to4 pseudointerface towards the relay.

An example:

05:46:20.480459 IP6 (hlim 127, next-header: TCP (6), length: 28) 
2001:0:4136:xxyy:34d4:282b:qwer:tyui.61333 > 
2001:0:4136:vvzz:10f1:3c6e:zxcv:bnmm.50372: S, cksum 0xed32 (correct), 
3553792932:3553792932(0) win 8192 <mss 1220,nop,nop,sackOK>

I wonder if other folks have seen stuff like this.

Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

More information about the ipv6-ops mailing list