Hacker News new | past | comments | ask | show | jobs | submit login

RA makes me extremely nervous. I am never quite confident that I haven't made a simple mistake that opens me up to rogue RA advertisements.

But SLAAC makes me equally nervous. If/when I shift my home network to IPv6, I'll probably just go with static routing to avoid both of them.




It's the switches job to drop traffic from rogue routers/DHCP servers. Look up RA Guard and DHCPv6 guard. You also need to worry about rogue DHCP(v4) servers too. DHCP Snooping takes care of that.

If you're that paranoid then you also need to worry about IPv4 ARP and IPv6 ND attacks. Again, managed switches are required to drop unauthorized ARP and ND replies.


> Look up RA Guard and DHCPv6 guard.

Yes, thank you. I'm aware of these features.

I never claimed that my nervousness is rational. But it's very real. This is complex stuff, and since I haven't been working with IPv6 for decades, I can't shake the fear that I've made a configuration error and am not aware that I've made a configuration error.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: