[146423] in North American Network Operators' Group
Re: ARIN-2011-1: ARIN Inter-RIR Transfers - Last Call (expires in
daemon@ATHENA.MIT.EDU (Jack Bates)
Fri Nov 11 15:10:53 2011
Date: Fri, 11 Nov 2011 14:10:32 -0600
From: Jack Bates <jbates@brightok.net>
To: Valdis.Kletnieks@vt.edu
In-Reply-To: <4923.1321038680@turing-police.cc.vt.edu>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On 11/11/2011 1:11 PM, Valdis.Kletnieks@vt.edu wrote:
> Would it be*nice* to have RA Guard and DHCP6 snooping in place? Yes. Is it
> totally impossible to deploy IPv6 until they're fully baked? Not at all - just
> need to be aware of the issues and be prepared to mitigate. Sure it raises the
> risk level slightly - but we judge the risks of not being well-positioned for
> IPv6 to be*much* higher.
From a DSLAM perspective, the security stuff was annoying and often
just broke IPv6 all together. I am still a fan of 1 vlan per user and
q-in-q. It does have issues in dorm type scenarios where you might not
want to bring local traffic all the way back to l3 termination, though.
Jack