best practices for management nets in IPv6

Cameron Byrne cb.list6 at gmail.com
Tue Jul 12 23:29:33 UTC 2011


On Jul 12, 2011 2:33 PM, "Tom Ammon" <tom.ammon at utah.edu> wrote:
>
> Hi All,
>
> We're pushing to get IPv6 deployed and working everywhere in our
operation, and I had some questions about best practices for a few things.
>
> On your management nets (network device management nets) , what's the best
approach for addressing them? Do you use ULA? Or do you use  global
addresses and just depend on router ACLs to protect things? How close are we
to having a central registry for unique local addresses, and will that
really happen?
>

ACL are prone to typos and inconsistent deployment. If the security policy
is that a give interface must not talk to the internet, ULA is a good choice
as part of a multi-layer security strategy

Cb
> Tom
>
>
-----------------------------------------------------------------------------
> Tom Ammon
> Network Engineer
> M: (801)674-9273
> tom.ammon at utah.edu
>
> Center for High Performance Computing
> University of Utah
> http://www.chpc.utah.edu
>
-----------------------------------------------------------------------------
>
>



More information about the NANOG mailing list