[195733] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IPv6 Loopback/Point-to-Point address allocation

daemon@ATHENA.MIT.EDU (Enno Rey)
Sun Sep 10 08:22:39 2017

X-Original-To: nanog@nanog.org
Date: Sun, 10 Sep 2017 11:53:20 +0200
From: Enno Rey <erey@ernw.de>
To: nanog@nanog.org
In-Reply-To: <59B50A19.9050806@foobar.org>
Errors-To: nanog-bounces@nanog.org

Hi,

On Sun, Sep 10, 2017 at 10:47:05AM +0100, Nick Hilliard wrote:
> Baldur Norddahl wrote:
> > Loopback interfaces should be configured as /128. How you allocate these do
> > not matter.
> 
> ..so long as there are interface ACLs on your network edge which block
> direct IP access to these IP addresses.

or, maybe even more efficient, assign all loopbacks from a dedicated netblock which you null-route on the edge/your border devices.

best

Enno


-- 
Enno Rey

ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de
Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 

Handelsregister Mannheim: HRB 337135
Geschaeftsfuehrer: Matthias Luft, Enno Rey

=======================================================
Blog: www.insinuator.net || Conference: www.troopers.de
Twitter: @Enno_Insinuator
=======================================================

home help back first fref pref prev next nref lref last post