Hi,

 

While going through the draft, I noticed there is no talk of tunneled ND message in the entire draft.

 

The draft states: -

 

   By setting the Hop Limit to 255, Neighbor Discovery is immune to
   off-link senders that accidentally or intentionally send ND messages.
 
However if we send a basic ND message in IP-in-IP tunneled packet and send the packet across, we can easily send ND messages off-link. A solution I can think of is that by default we SHOULD NOT allow ND packets inside tunneled packets unless explicitly configured to do so. 
 
Am I missing the point?
 
Thanks,
Vishwas
 




--------------------------------------------------------------------
IETF IPv6 working group mailing list
[email protected]
Administrative Requests: https://www1.ietf.org/mailman/listinfo/ipv6
--------------------------------------------------------------------

Reply via email to