Re: IPv6 supported?
Dave Evans <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Organization | House of Goodness |
| Message-ID | <[email protected]> |
on 08/07/2015 15:50, G.W. Haywood wrote: > Hi there, > > On Wed, 8 Jul 2015, Administrator wrote: > >> It would be very useful if IPCop acknowledged the existence of IPv6. >> Without that, there seem to be security risks ... > It is not clear to me that acknowledging (or otherwise) the existence > of IPV6 has any real bearing on security risks. From one of my /64s I > can assign to my toaster more IPV6 IPs than exist in the entire IPV4 > address space. But it's still just a toaster. Incidentally NAT does > not generally figure in IPV6 networks, so the whole world, if it is in > the slightest bit interested, can talk to my toaster and can know that > it's my toaster that it's talking to. Does the whole world care if I > have my toast very lightly done? Do I care if the world knows or not? > Can a miscreant burn my toast? The whole house? Is it security risk? > >> IPCop has VPNs "out of the box." Do they protect against these >> information leakage issues? > Your questions are vague. You need to be more precise with this kind > of thing. A VPN is essentially something which joins two private nets > in a private (for some meaning of 'private') way using a channel which > can be intercepted by third parties. The third party can tell when a > packet passes through the channel. That is information leakage of a > kind, in that the third party can tell that the VPN is in use. So a > burglar might infer from the week-long absence of traffic that you're > on holiday and it's a good time to burgle your flat. Security risk? > People have had their homes burgled because they'd forgotten to cancel > the daily milk delivery. > > If it should happen that the VPN client and server negotiate an > encryption key to use for the session, then the third party can > probably carry out what is called a 'man in the middle' attack, by > impersonating the client to the server and the server to the client. > When I use a VPN I would normally pre-share a private key using other > secure means to transfer the key. The man-in-the-middle attack is > much more difficult in that situation. I would not say that it is > impossible. I am only using VPNs to join private networks and to keep > secure the traffic between them - I am not particularly interested in > hiding the existence of any of the traffic between the sites, nor in > hiding the identity nor the 'public Internet browsing habits', nor > even the electronic mail of the users on those networks which I have > joined; and I am not generally working in countries with oppressive or > criminal regimes although many people in such countries routinely > attack (routinely unsuccessfully) the systems which I operate. > >> Can anyone with more understanding of these things comment? > As I said, your questions are vague. More than what? :) > If I recall correctly the security vulnerability paper which started this off (search for ipv6 vpn issues) seemed to be implying that if you're using a "VPN service" to connect to other network in such a way as to be untraceable, then any IPv4 traffic would travel down the VPN tunnel (and thus be encrypted & as secure as the implementation allowed) but some IPv6 traffic would potentially travel "beside" rather than "through" the VPN tunnel, it would all appear to work correctly, but the IPv6 traffic would be in the clear & vulnerable to snooping. On the face of it if IPCOP continues to ignore (and thus reject) all IPv6 packets either in or out, there can't be a risk, but the various transitional technologies (Teredo in Windows) might mean that IPv6 can get out of your network (encapsulated within a IPv4 packet) even though IPCOP doesn't directly support it. The simplest solution is to turn off IPv6 on all the clients behind IPCOP, but that may not be what you want. Dave ------------------------------------------------------------------------------ Don't Limit Your Business. Reach for the Cloud. GigeNET's Cloud Solutions provide you with the tools and support that you need to offload your IT needs and focus on growing your business. Configured For All Businesses. Start Your Cloud Today. https://www.gigenetcloud.com/ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user