El 27/06/12 09:19, Alex Efros escribió:
> Safe, but don't working. Do you enable ipv6 USE flag just to force people
> to either disable unintentionally enabled IPv6 in kernel and/or add this
> ip6tables configuration?
No, we do it because otherwise the stage3 is unusable on ipv6 only
environments and because people can still manually disable it.
> I suppose you enable ipv6 USE flag to make it
> easier for people to start using IPv6. But to use IPv6 these ip6tables
> rules doesn't helps - we really need docs how to setup IPv6 firewall in
> secure way, written by people who not just read IPv6 RFCs, but understood
> all security implications of IPv6-specific features. Last time I tried to
> google for such docs was few years ago, but I found nothing at all.
I couldn't indeed find a good firewall document for ipv4 so...

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to