Re: About IPv6 support

Tore Anderson <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <[email protected]>
* Alexandre Cassen <[email protected]>

> Current code support VRRPv2 for IPv6, I am working on integration of
> VRRPv3 (originally jonas patch). But, and But, I am not considering
> adding VRRP VIP into VRRP packet for a simple reason. This VRRP stack
> is widely used on critical production architectures, I am making a
> very extensive use of it in my day to day job too. And I am
> considering as a serious security issue placing those VIPs in each
> VRRP advert, because it simply expose key elements of your network
> architecture to potential attackers... You must hide as much as
> possible any info on your net arch, it a basic consideration. So
> until some one provide a valid proof of not doing it that way I will
> not add VRRP VIPs in VRRP adverts. It potentially broke bissection
> tools like wireshark, but this is not a good reason IMHO :D

Hi Alexandre,

RFC5798 requires that the addresses associated with the virtual router
is included in the VRRP packet. So if you decide to not do so, you'll
actually end up implementing something that is similar to, but not
quite, VRRP version 3. This might also break interoperability with
other VRRPv3 implementations such as Juniper and Cisco devices, making
it hard to migrate a network from these to Keepalived (or vice versa).

Finally I'd like to point out that for VRRPv2/IPv4, Keepalived already
*does* include the VIPs in the VRRP packets it transmits. So this
standard-compliant behaviour cannot really be considered a "serious
security issue"...

Tore

------------------------------------------------------------------------------
BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
Develop your own process in accordance with the BPMN 2 standard
Learn Process modeling best practices with Bonita BPM through live exercises
http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.