Requirements for IPv6 Firewalls

Simon Perreault simon at per.reau.lt
Tue Apr 22 12:01:28 UTC 2014


Le 2014-04-19 06:23, Florian Weimer a écrit :
>>> I agree with Bill.  You can poopoo NAT all you want, but it's a fact
>>> of most networks and will continue to remain so until you can make a
>>> compelling case to move away from it.
>>
>> Does that mean all IPv6 firewalls should support NAT?
> 
> In the sense that they "MUST be able to provide email filtering
> features": yes.

That requirement should be removed.

>> Remember, we're aiming for a base set of requirements applying to
>> all IPv6 firewalls.
> 
> The document has more than just base requirements.

The document is flawed as-is.

Simon




More information about the NANOG mailing list