OSPFv3 uses primarily local multicast and link local addresses for communications which are not routable. This significantly reduces the exposure to attack. Blocking OSPF and other IGP protocols at your border is still a good idea (even for v4).
Mack -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Mark Tinka Sent: Thursday, August 25, 2011 10:21 AM To: [email protected] Cc: Jon Lewis Subject: Re: [c-nsp] OSPFv3 authentication On Thursday, August 25, 2011 09:16:03 PM Jon Lewis wrote: > you get different lists of supported platforms, but both are pretty > small and lack any of the gear I'm interested in. Is everyone > using/moving to ISIS?...or just doing > OSPFv3 without authentication? IS-IS here with HMAC MD5 authentication, supporting both v4 and v6 with Multi Topologies. Mark. _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
