On Thu, 17 Jan 2002, Francis Dupont wrote:
> => we don't need to wait because mobile IPv6 is not yet fully specified.
> IMHO the only thing we need is to be ready and the first step should
> be to get (traditional) ingress filtering and firewalls with IPv6 support
> (or do you suggest to stop IPv6 until they are implemented and deployed?)

Ingress filtering and firewalls exist already.
 
>    Seems like this requires a two-phase approach: phase 1 before it is
>    available and phase 2 when/if it become available.
>    
> => you are acking what will happen after some kilometers in a deep fog:
> today only IPv6 raw protocol is available, not mobile IPv6, IPv6 ingress
> filtering, IPv6 firewalls, ...

You know full well that e.g. ip6fw, ipf, iptables (all free) etc. support
IPv6 ingress filtering and firewalling rather nicely; they've had the
support for some time now.  They're still a bit raw, as is understandable,
but usable.

So why do you spread FUD?

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Netcore Oy                   not those you stumble over and fall"
Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords

--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page:                      http://playground.sun.com/ipng
FTP archive:                      ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------

Reply via email to