Re: About IPv6 support

Alexandre Cassen <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <CAONz4a3YivuEzs5SfZ5S5fHdzLvap-zdcNefGgERqRj6fZizrQ@mail.gmail.com>
Salut Gilles,

This is a customer driven reason your side (commercial stuff here). You can
then consider sponsoring a release to make it happen or contribute.

Your proposition for the extension is valid.

regs,
Alexandre

On Thu, Apr 2, 2015 at 9:33 AM, Gilles Diribarne <
[email protected]> wrote:

> Hi Alexandre,
>
> If I understand what you mean, this is more a "philosophical" reason.
> You prefer to hide addresses because you have a security point in mind.
> This makes sense and I understand that !
>
> But, and But... ;-)
>
> We have made several tests.
> - When you are not in native_ipv6 and have IPv4 / IPv6 addresses, the
> IPv4 addresses are transmitted while the IPv6 are not transmitted. So,
> related to your point, it is a security issue (since the IPv4 addresses
> are visible on your network).
> - When you are using native_ipv6 and have IPv4 / IPv6 addresses, none
> address is transmitted.
>
> On our side, we have several customers that complain they cannot "read"
> the VRRP packet (which seems to be incomplete) and we would like to put
> these addresses in the VRRP packet. And, you know, when it's a customer
> who wants, ...
>
> We would like to contribute to the project. Keeping your security point
> in mind, I suggest that
> - We could add 'transmit_vip' keyword (in vrrp_instance) in order to put
> virtual addresses in the VRRP packet
>    This would be workable for you and for us.
> - When in IPv4 mode (not native_ipv6), the IPv4 (counted for 1 address)
> and IPv6 (counted for 4 addresses) are transmitted
> - When in IPv6 mode (native_ipv6), the IPv4 are expressed in IPv6
> compatible address (::IPv4), each counting 1
> - We could also add sanity checks to check the received packet
>    If the addresses are given and the check is more complete (take
> adresses into account)
> - When the keyword is not present, no address is transmitted into the
> packet (which would be the default mode)
>
> What do you think about that ?
> Gilles
>
>
> On 01/04/2015 14:59, Alexandre Cassen wrote:
> > Hi,
> >
> > Current code support VRRPv2 for IPv6, I am working on integration of
> > VRRPv3 (originally jonas patch). But, and But, I am not considering
> > adding VRRP VIP into VRRP packet for a simple reason. This VRRP stack
> > is widely used on critical production architectures, I am making a
> > very extensive use of it in my day to day job too. And I am
> > considering as a serious security issue placing those VIPs in each
> > VRRP advert, because it simply expose key elements of your network
> > architecture to potential attackers... You must hide as much as
> > possible any info on your net arch, it a basic consideration. So until
> > some one provide a valid proof of not doing it that way I will not add
> > VRRP VIPs in VRRP adverts. It potentially broke bissection tools like
> > wireshark, but this is not a good reason IMHO :D
> >
> > regs,
> > Alexandre
>
>
>
> ------------------------------------------------------------------------------
> Dive into the World of Parallel Programming The Go Parallel Website,
> sponsored
> by Intel and developed in partnership with Slashdot Media, is your hub for
> all
> things parallel software development, from weekly thought leadership blogs
> to
> news, videos, case studies, tutorials and more. Take a look and join the
> conversation now. http://goparallel.sourceforge.net/
> _______________________________________________
> Keepalived-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/keepalived-devel
>

------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/

_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.