[c-nsp] IPV6 in general was Re: Large networks

Alexander Clouter alex at digriz.org.uk
Fri Aug 28 15:18:10 EDT 2009


Alexander Clouter <alex at digriz.org.uk> wrote:
>
> Phil Mayers <p.mayers at imperial.ac.uk> wrote:
>>> 
>>> No, my routers do NOT send ra. I disable it as an incredibly insecure 
>>> mechanism.
>>> 
>> 
>> Fine - so point your clients statically at the virtual link-local 
>> address e.g. under Linux:
>> 
>> ip -f inet6 route add default via fe80::<the hsrp vip> dev eth0
>> 
>> What's the problem?
>> 
> Well, you should be using "ip route add 2000::/3 via....." ;)
> 
Bah, stumbled on RFC3587, I take that statement back :)

Cheers

-- 
Alexander Clouter
.sigmonster says: The best defense against logic is ignorance.



More information about the cisco-nsp mailing list