ICMP(v6) filtering?

Daniel Roesen dr at cluenet.de
Wed Aug 8 10:42:00 CEST 2012


On Wed, Aug 08, 2012 at 10:28:05AM +0200, Marco Hogewoning wrote:
> > But is there a cunning plan to stop address sweeping attacks that cause a lot
> > of neighbor solicitations and cache entries? We already have this problem with
> 
> Simply rate limit ND?

It's not as simple as that, otherwise it would be a non-issue. See RFC
6583 for a discussion of the problem, especially section 6.4.


Best regards,
Daniel

-- 
CLUE-RIPE -- Jabber: dr at cluenet.de -- dr at IRCnet -- PGP: 0xA85C8AA0



More information about the ipv6-ops mailing list