Re: Strange IPv6 Routing Behaviour[LONG]

2002-06-08 Thread Michael Richardson
? ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another NetBSD/notebook using, kernel hacking, security guy

Re: Recovering from multiple routers advertising routes

2003-05-20 Thread Michael Richardson
. But, see draft-richardson-dhc-auth-sig0-00.txt My problem is that my Debian box with Linus kernel frequently does *not* install a default route from the RS given out by my NetBSD router. ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman

Re: Recovering from multiple routers advertising routes

2003-05-23 Thread Michael Richardson
requirements for manual configuration. ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(Just another Debian

Re: Routing with 6to4 *and* a tunnel

2005-06-25 Thread Michael Richardson
the Marc 6bone and receive replies using 6to4? I understand that The Marc routes will be asymmetric. I've done it. Watch ingress filtering though. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see

Re: Routing with 6to4 *and* a tunnel

2005-06-26 Thread Michael Richardson
multiple networks, and my NetBSD boxes did fine with it. (in particular, I had multiple ones when transitioning from one 6to4 address to another). That's when I learnt how bad the Linux source address selection is. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls

Re: Routing with 6to4 *and* a tunnel

2005-06-27 Thread Michael Richardson
space, is that you get to own it. You then use the tunnel for 2001: (in my case, I listen to BGP from Hurricane...) People's data coming back to you follow 6to4 traffic, and so follow ipv4, and thus tend to get places fast. - -- ] Michael Richardson Xelerance Corporation

Re: Routing with 6to4 *and* a tunnel

2005-06-27 Thread Michael Richardson
connectivity. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm a dad: http

Re: Routing with 6to4 *and* a tunnel

2005-06-27 Thread Michael Richardson
the IPv4 network. Yes, that's right. If you can't get native IPv6, 6to4 is better than tunnels. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr

Re: Routing with 6to4 *and* a tunnel

2005-06-28 Thread Michael Richardson
job in the US and nowadays also European Jeroen region: http://www.occaid.org. Jeroen If you just need connectivity, and you are in Europe you are Jeroen of course also welcome to check SixXS: http://www.sixxs.net Thanks for the pointers. - -- ] Michael Richardson

Re: Is there agreement on ddns (or any such) with autoconfigured hosts?

2005-06-28 Thread Michael Richardson
. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm a dad: http://www.sandelman.ca

Re: Routing with 6to4 *and* a tunnel

2005-06-28 Thread Michael Richardson
with them and be done with it. True, getting a static v4 can be hard --- IPsec can easily help there, but that is introducing yet another tunnel. My suggestion is always to seek another ISP that will give you a static IP. - -- ] Michael Richardson Xelerance Corporation, Ottawa

Re: Is there agreement on ddns (or any such) with autoconfigured hosts?

2005-06-28 Thread Michael Richardson
is done by the DHCP server, which has a trust relationship with the owner of the IP address range it is handing out. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http

Re: Is there agreement on ddns (or any such) with autoconfigured hosts?

2005-06-28 Thread Michael Richardson
replicate the model. If we are using RS/RA, then we have to find a way for the RS to have a trust relationship with the owner of the reverse zone. That part is easy --- the question is how does the RS even know about the new clients? - -- ] Michael Richardson Xelerance Corporation, Ottawa

Re: Is there agreement on ddns (or any such) with autoconfigured hosts?

2005-06-29 Thread Michael Richardson
sincerely hope the IETF multi6 WG eventually proposes significant changes, but there are not at this point any difference to the transport layer between them. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training

Re: Setup of private IPv6 addresses

2005-09-02 Thread Michael Richardson
(live) CD on a system and see if it does better. I have much better luck with IPv6 on *BSD, alas. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http

Re: Setup of private IPv6 addresses

2005-09-04 Thread Michael Richardson
to manually configure all my Linux boxes now, so I only give them one address... so maybe my memory is wrong. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED

Re: why?

2006-07-06 Thread Michael Richardson
happy. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using

Re: How to disable ipv6 in Lenny to avoid 1.0.0.0 in name resolution for AAAA type queries?

2007-12-15 Thread Michael Richardson
. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(Just another Debian GNU/Linux using, kernel hacking, security guy); [ -BEGIN PGP SIGNATURE- Version: GnuPG

FYI ic.gc.ca task force on IPv6

2009-07-20 Thread Michael Richardson
ISACC: http://www.isacc.ca/ The ISACC IPv6 Task Group will reconvene via teleconference as follows: Date: 21 July 2009 Time: 13:30h - 14:30h EDT Dial-in number: +1-613-954-9003 , Passcode: 352654# If you intend to dial in, please ensure you RSVP , if you have not done

Re: Possible IPv4 LAN NAT Routing to native IPv6?

2009-12-17 Thread Michael Richardson
. If it is being done automatically, I'm not sure what to suggest. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device

Re: IPv6 proxy browsers??

2010-03-22 Thread Michael Richardson
of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto Plus: watch the video http://www.youtube.com/watch?v=kzx1ycLXQSE

IPv6 and XEN scripts

2010-06-14 Thread Michael Richardson
of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto Plus: watch the video http://www.youtube.com/watch?v=kzx1ycLXQSE then sign

Re: IPv6 and XEN scripts

2010-06-15 Thread Michael Richardson
of this now. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto Plus: watch the video http

Re: IPv6 and XEN scripts

2010-06-18 Thread Michael Richardson
is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto Plus: watch the video http://www.youtube.com/watch?v=kzx1ycLXQSE

Re: IPv6 and XEN scripts

2010-06-18 Thread Michael Richardson
! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto Plus: watch the video http://www.youtube.com/watch?v=kzx1ycLXQSE then sign the petition

Re: Security of 6to4 (was: Re-prioritizing 6to4 over v4 addresses)

2010-09-23 Thread Michael Richardson
end-to-end integrity, we have IPsec, and you can even usefully use AH thanks to the lack of NAT. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http

Re: Thoughts about RA en DHCPv6 in /etc/network/interfaces

2010-12-08 Thread Michael Richardson
, and I want to know about them all. (vs IPv4, with VRRP/CARP or old-school RIP or OSPF...) -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http

IPv6 across suspend / resume -- who is responsible for flushing?

2011-05-17 Thread Michael Richardson
the essid is changed? Should NetworkManager be doing this? I'm running squeeze, with 2.6.32-bpo.5-686. (because I got here upgrade From lenny+backports) -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa

Re: IPv6 across suspend / resume -- who is responsible for flushing?

2011-05-17 Thread Michael Richardson
, so it's possible I'm missing some element. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto

Re: [vserver] assigning less than /64 to individual guests

2011-05-17 Thread Michael Richardson
to work seems like a nice thing to retain. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ Kyoto

Re: [vserver] assigning less than /64 to individual guests

2011-05-17 Thread Michael Richardson
that work? I think that you just want autoconfig to work well enough so that if you install a new machine in the rack, it can autoconfig up an address easily, and you can finish the install via ssh :-) -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael

Re: IPv6 and DNS

2011-07-13 Thread Michael Richardson
What I've wanted is for avahi-daemon to do dynamic DNS updates into forward and reverse based upon what it sees on the network. Or have radvd do this. -- To UNSUBSCRIBE, email to debian-ipv6-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

NFS and RPC over IPv6

2011-09-27 Thread Michael Richardson
need showmount and friends to work as well, because I used autofs. Can someone point me to a plan that I can contribute to? -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m

Re: IPv6 linklocal address on bridged interfaces

2012-03-24 Thread Michael Richardson
) I'd prefer if the member devices of a bridge had their link-local addresses removed by the kernel when they get added to the bridge. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect

Re: auto6to4

2012-07-03 Thread Michael Richardson
Andrew == Andrew Shadura bugzi...@tut.by writes: Andrew On Wed, 06 Jun 2012 11:04:04 -0400 Michael Richardson Andrew m...@sandelman.ca wrote: Miredo is almost always more reliable. Andrew I don't agree. It's more reliable in that meaning that in Andrew works regardless

Re: IP sent by DNSv6 Server

2013-02-26 Thread Michael Richardson
. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ -- To UNSUBSCRIBE, email to debian-ipv6

Re: IPv6 status on Debian for workstations / DHCP networks?

2013-07-05 Thread Michael Richardson
can't comment. Should NetworkManager and the interfaces file always bring up both IPv4 or IPv6 whenever possible or is it just one or the other? both. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

Re: Questions on IPv6 stateless autoconfiguration

2014-11-22 Thread Michael Richardson
; there isn't a way to do this automatically... yet. See MIF/HOMENET problem statements. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca

Re: Questions on IPv6 stateless autoconfiguration

2014-11-23 Thread Michael Richardson
answer? Am 11/23/2014 01:06 AM, schrieb Michael Richardson: Jan Lühr f...@jluehr.de wrote: Consider three Debian servers (A,R1,R2) and two networks. A is connected to both networks using different NICs. R1 is a router in network 1, while R2 is a router in network 2

Re: Using IPv6 and ULA for greater resilience

2017-05-14 Thread Michael Richardson
WG has done work to make this work when you have multiple uplinks, and multiple routers with-in the "home", and do this in a zerotouch way. There are many opportunities to contribute to this effort. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Mich

enabling net.ipv4.tcp_mtu_probing=2 on Debian servers

2017-09-19 Thread Michael Richardson
cal process involved. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature

Re: Where's the documentation?

2018-05-13 Thread Michael Richardson
| ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

DHCPv6-PD requests, and virtual machines

2021-09-01 Thread Michael Richardson
. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature

Re: Limit the number of Router Advertisements processed on an interface

2022-06-15 Thread Michael Richardson
Dheeraj Kandula wrote: > *Why?* > This is to avoid DOS attacks using RAs from being bombarded onto a linux > machine. Well, you might be able to rate limit them with ip6tables/nftables, but I see no point in only listening to the first X of them. You might as well just disable them