Re: IPv6, IPSEC and DoS

From: Iljitsch van Beijnum (no email)
Date: Sun Jan 02 2005 - 05:26:09 EST

  • Next message: Edward B. Dreger: "Re: BGP 011: multiple sessions with upstreams"

    On 2-jan-05, at 4:07, wrote:

    >> No, that list is just a starting point for the discussion. A lot of
    >> stuff in the list doesn't amount to anything. (For instance, there is
    >> no ARP in IPv6.)

    > Yeah, ARP is basically one machine yelling "Who has this IP?" and
    > another
    > one answering "ME!! ME!!". In IPv6, there's something called "Neighbor
    > Discovery" where one machine yells "Who has this address?" and another
    > one
    > yells back "ME!! ME!!". Totally different things :)

    The base functionality is obviously the same. It's implemented quite
    differently, though.

    > (Note that they both do the exact same thing to make sure the correct
    > machine is yelling "ME!! ME!!"....)

    Really? So ARP uses SEND? (
    http://www.ietf.org/html.charters/OLD/send-charter.html )

    (Although living in a hostile subnet isn't something I would recommend
    in the first place. Being on the same link opens way too many
    additional attack vectors.)


  • Next message: Edward B. Dreger: "Re: BGP 011: multiple sessions with upstreams"





    Hosted Email Solutions

    Invaluement Anti-Spam DNSBLs



    Powered By FreeBSD   Powered By FreeBSD