Re: recommendation on DHCP6 source port numbers
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.dhc |
|---|---|
| Message-ID | <[email protected]> |
[email protected] <[email protected]> wrote: > David, I can see that argument. But we also didn't think randomized > source ports were going to be important for DNS... I guess I don't see > why we should be declaring what an implementer does on the source port We expect DNS messages to leave the "enterprise" (site) and get returned to us. We require it for DNS to work. It's the whole point. Yes, there was a point in the past where many DNS requests were *from* port-53. DHCPv6: not so. Just the opposite. OpenWRT actually blocks port 546/547 from being accepted on the wan interface, unless it's LL. (zone_wan_input) If DHCPv6 leaves the local link, it's because there is a DHCP relay configured. So I feel confident that we will NEVER need clients to port randomized source ports. We *might* decide that there is some scenario where we want a DHCPv6 *RELAY* to do something like that, but I'll bet we won't do that without a DTLS or IPsec wrapper. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ dhcwg mailing list [email protected] https://www.ietf.org/mailman/listinfo/dhcwg
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmXhKVUWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZXj1B/4+s7udRnMytmaiyBbKj7/xl4ak laU5oPOVz5ZDT5UU2grblr1foyFgimbaB9KMnYFxvsHc72Qit41JxoqWAeVwvywo l4QIj9kw8nWsWMcyT/3Rxr5DbEQd/s/8pz2V5FoTMZFUPy09KWRLl52MlS+OS02W 03FoisLmvdiaL8WjB6vdpH5Kk1saHgHZCj/+yHrX7Q2PuG+dCbc3UCRKczuY4F8z FU3tCKrKS2BxUiwjO5xdpt9QrC3a8DYIpaNoHKl1Kbj3Xqf4IhezqCOFFfRT+d5e F2v5Z5RgoB1pYJKaW1DloLP71F1wx/Qu7nLhaV5puCRw9Lxn4U4/1htqAfmB =J0rE -----END PGP SIGNATURE-----