On 2026-09-22 15:14:40 +0200, Marco Moock wrote: > Am 22.09.26 um 15:00 schrieb Vincent Lefevre: > > Exactly. Of course, at that time, I asked the admins to take measures > > to filter RAs. They answered me something like this was not possible > > with their old routers (which might be the same reason why we still > > do not have IPv6 here: old material, but also too few admins to take > > care of the problems). I don't know whether things have improved > > since 2015, but a few months ago (in March), on one of my machines, > > a "nameserver fe80::a4cf:99ff:fe46:c64%enp0s25" line appeared in > > /etc/resolv.conf (generated by NetworkManager), apparently due to > > some rogue RA. > > Be aware that there is a high risk that someone does MITM attacks. Maybe > tell that the security department, the might care more than the regular > admins.
I know, and the admins of the ENS-Lyon network (who are also in charge of the security at this level) probably know that too. That's why ignoring RAs is important, and the lack of official documentation of how to do that (and the surprising behavior of existing options) may lead to the radical solution of disabling IPv6 in the kernel. -- Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

