Добро пожаловать, Гость. Пожалуйста авторизуйтесь здесь.
FGHIGate на GaNJa NeTWoRK ST@Ti0N - Просмотр сообщения в эхоконференции IPV6
Введите FGHI ссылку:


Присутствуют сообщения из эхоконференции IPV6 с датами от 31 Jul 11 14:37:00 до 03 Oct 24 21:46:09, всего сообщений: 7440
Ответить на сообщение К списку сообщений Предыдущее сообщение Следующее сообщение
= Сообщение: 3342 из 7440 ============================================= IPV6 =
От   : Michiel van der Vlist            2:280/5555         08 Aug 16 22:11:52
Кому : Tony Langdon                                        08 Aug 16 22:11:52
Тема : IPV6 and Netgear
FGHI : area://IPV6?msgid=2:280/5555+57a8ee36
На   : area://IPV6?msgid=1795.fido-ipv6@3:633/410+1c0d4c97
= Кодировка сообщения определена как: CP850 ==================================
Ответ: area://IPV6?msgid=1803.fido-ipv6@3:633/410+1c0e55aa
==============================================================================
Hello Tony,

On Monday August 08 2016 14:34, you wrote to me:

MvV>> Any decent IPv6 capable router should have a firewall that
MvV>> blocks all unsollicited incoming IPv6 packets by default, but
MvV>> allows to "punch holes" depending on port numbers and
MvV>> destination on the LAN.

TL> This is how my Fritzbox works.  Confusingly, the call it "port
TL> forwarding" (under the IPv6 tab), but it's actually a packet filter.

This confusing way of presenting the IPv6 firewall options seems to be common among router manufacturers. I have a combined Cable modem + router from Cisco. There is a tab "security" with a subtab for "firewall". That allows for enabling or disabeling the IPv6 firewall. Also enabling things like enabeling port scan detection, amd flood detection.

In a completely dirfferent part there is a tab "Applications and gaming" there is a section "Port Range Frowarding". IPv4 and IPv6 are covered in one and the same section. You choose and external port range (start port and end port) an internal IP adress, the IP type, internal port range and protocol (TCP/UDP/Both).


For IPv4 it is old hat. But when you change the IP type there are two other choices, IPv6 or MACv6. If you choose one of these the boxes for the external port range gray out. You can only enter an internal port range. That one can not eneter both an external and an internal port range makes sense, there is no port /translation/. But it is confusing at first because the external port range is the two most left boxes, which one naturally would try to enter first.

The internal IPv6 address defaults to ::. Which in a way also makes sense. Interesting is the option "MACV6". Instead of the IPv6 addres, one enters the MAC addres of the interface. Usefull if one does not hava a static IPv6 prefix. Then you do not have to change the table every time the IPv6 prefix changes.

I can understand why they do it this way, but I find it undesirable from an edecucational POV. While it hase the same goal: having an uncoming packet reach its inteded destination, the mechanism is completely different. As you say for IPv6 it is not NAPT, it is a packet filter.

TL> There are options to allow TCP and/or UDP ports, or you can expose the
TL> host completely if you prefer (i.e. disable all inbound filtering for
TL> that particular IP).  I have a handful of exposed Linux hosts, and for
TL> this Windows machine, only a couple of ports (telnet, rlogin and SSH)
TL> that were used for testing are unfiltered.  By default, out of the
TL> factory, all inbound IPv6 traffic is blocked, which is the most
TL> sensible default.

Same with my router.

What is a bit unclear is how it deals wikt ICMP. There is an option in the firewal setting "block anonymous internet requests". It is unclear if it applies to both IPv4 and IPv6 or to both. It is activated by default. By default it rejects PING.  So I have deactivated it and now all IPv6 devices on the LAN are pinagble. It has no way to be more specific, so I assume all ICMP is allowed.


Cheers, Michiel

--- GoldED+/W32-MSVC 1.1.5-b20130111
* Origin: he.net certified sage (2:280/5555)

К главной странице гейта
Powered by NoSFeRaTU`s FGHIGate
Открытие страницы: 0.042401 секунды