Gi Firewall for mobile subscribers

Tore Anderson tore at fud.no
Thu Apr 11 07:23:26 UTC 2019


* Owen DeLong

> What would be the process for a subscriber who wishes to allow inbound connections?
> 
> If you are simply saying that as a customer of your ISP you simply can’t allow inbound IPv6 connections at all, then you are becoming a very poor substitute for an ISP IMHO.

I have to agree with this.

We've been wanting to replace our all of our ad-hoc OOB links with a
standardised setup based on LTE connectivity to an embedded
login/console server at each PoP. IPv6 would be perfect due to no
CGNAT and infinitesimal levels of background scanning.

Unfortunately Telenor has decided to deploy a central firewall that
drops all inbound connections, making their service totally unusable
for our use case. I guess they don't want our money.

Maybe with EU RLAH I could simply find another more suitable provider
abroad. Maybe I'd even get vPLMN redundancy that way. Hmm...

Tore



More information about the NANOG mailing list