[147863] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IPv6 RA vs DHCPv6 - The chosen one?

daemon@ATHENA.MIT.EDU (Mohacsi Janos)
Fri Dec 23 16:37:43 2011

Date: Fri, 23 Dec 2011 22:36:44 +0100 (CET)
From: Mohacsi Janos <mohacsi@niif.hu>
To: Jeff Wheeler <jsw@inconcepts.biz>
In-Reply-To: <CAPWAtb+NA1Sc03o9U25qXUqQFOv2=aK2WXvJvu2v48ZsXYcbfQ@mail.gmail.com>
Cc: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--0-236134731-1324676205=:99152
Content-Type: TEXT/PLAIN; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8BIT




On Fri, 23 Dec 2011, Jeff Wheeler wrote:

> On Fri, Dec 23, 2011 at 4:13 PM, Mohacsi Janos <mohacsi@niif.hu> wrote:
>> If you can limit number of ARP/NDP entries per interfaces and you complement
>> RAGuard and DHCPv4 snooping your are done.
>
> That depends on how ARP/ND gleaning works on the box.  In short, Cisco
> already has a knob to limit the number of ND entries per interface on
> some of their kit, and it is not a solution, only a damage mitigation
> measure.  http://inconcepts.biz/~jsw/IPv6_NDP_Exhaustion.pdf


The solution is that you monitor your device: if limits reached then you 
get notified and you can resolve the problem.
 	Best Regards,
 		Janos Mohacsi

>
> -- 
> Jeff S Wheeler <jsw@inconcepts.biz>
> Sr Network Operator  /  Innovative Network Concepts
>
>
--0-236134731-1324676205=:99152--


home help back first fref pref prev next nref lref last post