Le 8 mai 2014 à 19:05, Brian Candler <[email protected]> a écrit :
>> On the WAN interface, I’m currently allowing full ICMPv6 in, albeit only >> from Global Unicast and Multicast addresses. >> That is: only from 2000::/3 and ff00::/8. > I don't think you'll see any packets with multicast source addresses. It's > possible you could see packets with Link-Local source addresses (fe80::/64) > from the upstream router, but you may not care. Thanks. They (upstream router) confirmed I can drop their eventual link-local ICMPv6 packets. Allowing multicast source addresses is indeed probably needless. __ Olivier Mascia tipgroup.com/om _______________________________________________ List mailing list [email protected] https://lists.pfsense.org/mailman/listinfo/list
