[j-nsp] IPv6 RE protection

Cydon Satyr cydonsatyr at gmail.com
Sun Apr 26 05:32:48 EDT 2015


Thanks, I will check those out.

Do you consider not having IPv6 filter on RE a big security issue? Do you
use it on your routers?

BR

On Sun, Apr 26, 2015 at 4:49 AM, Michael Loftis <mloftis at wgops.com> wrote:

>
>
> On Saturday, April 25, 2015, Cydon Satyr <cydonsatyr at gmail.com> wrote:
>
>> Hello,
>> Currently we don't use any IPv6 RE protect filters on our routers (6PE
>> only
>> in network). We do use IPv6 filters on public interfaces, however.
>> Would you recommend deploying IPv6 RE filters on our edge routers at
>> least.
>>
>> What kind of configuration you have in your network?
>>
>> Also, do you know if Juniper still only supports matching on one
>> next-header?
>
>
> Depends on your hardware. MPC can dig a bit more precisely but DPC is
> limited (hardware)
>
>
> http://www.juniper.net/documentation/en_US/junos14.2/topics/reference/general/firewall-filter-match-conditions-for-ipv6-traffic.html
>
>
>
>
>>
>> Best Regards community
>> _______________________________________________
>> juniper-nsp mailing list juniper-nsp at puck.nether.net
>> https://puck.nether.net/mailman/listinfo/juniper-nsp
>>
>
>
> --
>
> "Genius might be described as a supreme capacity for getting its possessors
> into trouble of all kinds."
> -- Samuel Butler
>
>


More information about the juniper-nsp mailing list