Hi,

In the latest draft version, Section 3.5 says:

  "As a result, blocking ISATAP by preventing hosts from
   successfully performing name resolution for the
   aforementioned names and/or by filtering packets with
   specific IPv4 destination addresses is both difficult
   and undesirable."

I would like to understand this better. In particular, the
ISATAP service is by design disabled by disabling name
resolution for the name "isatap.domainname" and/or by
disabling the ISATAP router advertisement service. Can
you say why this would be difficult and undesirable?

Thanks - Fred
[email protected]
_______________________________________________
OPSEC mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/opsec

Reply via email to