Re: [opensuse] IPv6 firewall



Hans Witvliet wrote:
He noticed that he got from his ISP directly, both a V4 AND a V6
address, without even being told about the possibility!
Did he actually get an IPv6 address from the ISP? Or did he just notice the link local IPv6 address. A quick test for IPv6 internet is to try to go to ipv6.google.com.

So the lesson for lot's of people: even if you're not using (knowingly)
IPv6, configure your firewall for it.
My Linux box firewall is configured to pass only ssh, OpenVPN and the 6to4 tunnel on IPv4. When I port scan my computers that are behind the firewall, but have an IPv6 address, I can see all the open services, not just those I want available on the internet. That's something I'll have to get around to resolving soon.
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • IPv6 Woes...
    ... I have a router that doesn't support IPv6 yet, so my ISP and I setup a gif tunnel, which is working great. ... My LAN cannot ping my IPv6 address on the firewall, or, of course, my ISP. ... inet xxx.xxx.xxx.xxx netmask 0xfffffff0 broadcast xxx.xxx.xxx.xxx ...
    (freebsd-net)
  • Re: ipv6 question
    ... connection now has a nice, routable IPv6 address back to the machine ... now have to have to be routed through an external IPv6 SPI firewall ... you've got a webserver, it can see if you've got a mail server, etc. ...
    (Fedora)
  • Re: Firewall or Little Snitch
    ... In Airport Utility, click on Internet at the top. ... At the bottom of the Internet Connection settings is "Connection ... firewall due to the NAT translation. ... You should also turn off external access to IPv6, ...
    (uk.comp.sys.mac)
  • Re: FreeBSD Firewall/Router/Gateway questions.
    ... It really does seem to depend on where in the Internet one is connected. ... the how-to for setting up and running an IPv6 firewall? ... ISP's are happy to sell NAT ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Im I being targeted?
    ... But the packets did not occur at the correct time, ... As far as IPv6... ... firewall and Internet Connection Firewall can't block IP version 6 ... causing a lockup of my home DSL and/or router, ...
    (comp.security.firewalls)