[75502] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IPV6 renumbering painless?

daemon@ATHENA.MIT.EDU (Christopher L. Morrow)
Sat Nov 13 22:10:22 2004

Date: Sun, 14 Nov 2004 03:09:52 +0000 (GMT)
From: "Christopher L. Morrow" <christopher.morrow@mci.com>
In-reply-to: <40FDB4D0-3572-11D9-9D6A-000A95CD987A@muada.com>
To: Iljitsch van Beijnum <iljitsch@muada.com>
Cc: Henning Brauer <hb-nanog@bsws.de>, nanog@merit.edu
Errors-To: owner-nanog-outgoing@merit.edu


On Sat, 13 Nov 2004, Iljitsch van Beijnum wrote:
> On 13-nov-04, at 10:02, Henning Brauer wrote:
>
> Filtering based on IP addresses is a broken concept.
>
> I'm not a huge fan of sprinkling crypto over everything, but if you
> want certain people to have access to some stuff and not others,
> IPsec/SSL are the way to go.

there are things putting random packets over the network today, trying to
exploit services you might be using, or your customers might be using.
IPSEC everywhere is 'nice' but not horribly practical. SSL is nice, until
your SSL libraries have remotely exploitable DoS or root
vulnerabilities... how many times over the last 12 months has openssl been
upgraded due to 'security' issues?

home help back first fref pref prev next nref lref last post