Current IPv6 deployment methods in datacentres.

Gert Doering gert at
Mon Nov 12 15:15:57 CET 2012


On Mon, Nov 12, 2012 at 02:13:54PM +0000, Nick Hilliard wrote:
> On 12/11/2012 14:11, Phil Mayers wrote:
> > You also run into ACL label limits in big installs (you can have many fewer
> > labels the SVIs, and burn one label per interface type & ACL combo).
> what worries me more on the sup72 0 is the inability to block ipv6 fragments.

For transit fragments, I don't really care - we're not the Internet's
firewall.  For fragments destined to the router CPU, yeah, that's bad,
especially coupled with insufficiently granular CoPP for IPv6.

Is that fixed in more recent gear (Sup-2T, ASR9k, Nexus7k)?

Gert Doering
        -- NetMaster
have you enabled IPv6 on something today...?

SpaceNet AG                        Vorstand: Sebastian v. Bomhard
Joseph-Dollinger-Bogen 14          Aufsichtsratsvors.: A. Grundner-Culemann
D-80807 Muenchen                   HRB: 136055 (AG Muenchen)
Tel: +49 (89) 32356-444            USt-IdNr.: DE813185279

More information about the ipv6-ops mailing list