On 19.01.2012 09:48, Mohacsi Janos wrote:
> Which is more frequent, renumbering or tweaking firewall rules? There 
> is a tradeoff - everybody should decide according their taste. 

In my opinion firewalls should change their behaviour in flexible rules. 
I don't want to enter the prefix explicitly in each rule but only the 
host part.

I configure my currently prefix 2001:db8::/48 as prefix-set MY-NETWORK.
In a rule I only use MY-NETWORK:dead:beef:0:1.

On the big day of prefix change I advance my prefix-set by simply adding 
the new prefix - letting the old one still there..
After the renumbering phase I simply delete my old prefix 2001:db8::/48 
from the prefix-set and I'm done.

Firewalls have to change for real ipv6 ops.

And by the way: I really don't care for my servers on the renumbering 
day. They are all static configured but managed by puppet. Changing the 
ip will just be a small script.

