Re: About IPv6 support (Alexandre Cassen)

Alexandre Cassen <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <CAONz4a0eUfetZ5sZR15Zr9Ei54KyCseo+XOkMj9tA8e=EUOA0Q@mail.gmail.com>
Hi Colin,

Your point is correct if your are considering multicast use-case, in the
unicast use-case which is really largely used on virtual infrastructures
and VM, the best you minimize infos in your adverts the best you are
because on transit there might be multiple hop and some of them are just
not under control at all (this is the reason why IPSEC-AH is strongly
encouraged here).

But I must agreed, this can definitely be a configuration tweaking feature.

regs,
Alexandre

On Thu, Apr 2, 2015 at 11:11 AM, Colin Docherty <[email protected]> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi Alexandre,
>
> On 04/02/2015 08:33 AM, [email protected]
> wrote:
> > On 01/04/2015 14:59, Alexandre Cassen wrote:
> >>> Hi,
> >>>
> >>> Current code support VRRPv2 for IPv6, I am working on
> >>> integration of VRRPv3 (originally jonas patch). But, and But, I
> >>> am not considering adding VRRP VIP into VRRP packet for a
> >>> simple reason. This VRRP stack is widely used on critical
> >>> production architectures, I am making a very extensive use of
> >>> it in my day to day job too. And I am considering as a serious
> >>> security issue placing those VIPs in each VRRP advert, because
> >>> it simply expose key elements of your network architecture to
> >>> potential attackers...
>
> I can see your logic here with regard the VIP, however I don't think
> its worth compromising the standard, as there are already larger
> security issues that need to be addressed appropriately on the
> network. There is no real way to hide the VIP from the network as
> ARP/ND is always making this information public to the network. I have
> worked on VRRPv(1-3) for about 12 years, and I totally agree with the
> statement in (Section 9 - Security Considerations) of RFC5798
> (VRRPv3). If someone has access to the LAN without "switch port level"
> security then your already potentially compromised, and there's
> nothing stopping them from manipulating ARP and ND. It is also for
> this reason that VRRPv3 drops authentication completely. The only safe
> way to secure a network with VRRP is to implement controls at the
> switch, restricting ARPs/NDs for the VIP.
>
> You must hide as much as
> >>> possible any info on your net arch, it a basic consideration.
> >>> So until some one provide a valid proof of not doing it that
> >>> way I will not add VRRP VIPs in VRRP adverts. It potentially
> >>> broke bissection tools like wireshark, but this is not a good
> >>> reason IMHO :D
>
> Cheers!
> Colin.
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (GNU/Linux)
>
> iQIcBAEBAgAGBQJVHQfeAAoJENw9pS6LszPMI+8QAJMlhKQlprWafRQetgiZHufV
> zpnDcLj7weXjpmYEezTy1ZEeBcVGzPbehHhoUnkHzgy8llhdKEjBM0EBsCg3qmzF
> LXEUVzqLQaFcA6OwQVxuVs5aNqz8368ep8MBraOWYsQ6bpu8UogjDQTqV3lZ+0Ik
> n//mkxN0iXq6d967dXwnajy+83jKK+4a8sU2GPlAAp4d0mCtL3uaMgzs+eTLeb+6
> lyHNgTM2o69i/cNAmdIOdJjTGEVUq2fnqGP/qKjX3TMdZQ3l9Rft4yReOUuXjUPR
> MG2TMxg8zuOVxx916GLIb9MYo+7vL14utU25/7KBzI5zD8PdOHgVqww+4++STv8B
> WgslGvzl2czSwTDSbS6oT1JQ7J9VctoXKiTwbgxqA8FeX35KB50xZH+1Gzw7/E06
> r+Os5VwCSUX3ReivWMpGvRKBKvbTj1xmKYTVUhU/p8U8v9MS/jf1wEOhRDhPp5+E
> eF6kpORwhbFpRzK4OdxLLGHRqavxoaHB5xYKDTbe+wf/lUI0vs2EDmZNLWYefa+N
> gE4uw84cwyYYaTjuaxenZ4KKVL9TKNTuZVZ5yDlc7LrumDwZBHaMmlyhJ+4zkPFU
> I3lqp0/0z9nvutqHT6t9jhsv1w5t3us+ZQKbN82mj/K5T0Bq/78FfwU0MD+yKkUO
> EXH09J9ZVQ8gMC139hUk
> =yC1y
> -----END PGP SIGNATURE-----
>
>
> ------------------------------------------------------------------------------
> Dive into the World of Parallel Programming The Go Parallel Website,
> sponsored
> by Intel and developed in partnership with Slashdot Media, is your hub for
> all
> things parallel software development, from weekly thought leadership blogs
> to
> news, videos, case studies, tutorials and more. Take a look and join the
> conversation now. http://goparallel.sourceforge.net/
> _______________________________________________
> Keepalived-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/keepalived-devel
>

------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/

_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.