>>>>> On Tue, 2 Mar 2010 10:37:25 -0500, Robert Story <[email protected]> 
>>>>> said:

[re: IP address lookups of com2sec returning both v4 and v6 addrs]
MF> If not I  would like to know what action to take:
MF> 
MF> 1) Keep it as is
MF> 2) Make both add all addresses
MF> 3) Make both add only the first returned address

RS> Hmmm... I'd vote for 2. If we did 3, then we should log a warning that only
RS> the first address was used.

That does seem a behavior change though.  If people are intentionally
limiting stuff to v4 only for security architectural purposes in their
network (ok, I admit I doubt anyone actually is) then they'll suddenly
start accepting new packets that they didn't previously.  Consider the
case where the v4 space is NATed and somewhat protected but v6 is fully
routable (a common situation).

Maybe adding a new token to do both would be the right way to go.
-- 
Wes Hardaker
Please mail all replies to [email protected]

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

Reply via email to