RE: IPv6 Allocation Policy
"Michel Py" <michel-nyboWHt8SIrJRljzj3WzodHdOEOI8IWic20RSKp2L0g@public.gmane.org>
| Newsgroups | gmane.org.apnic.global-v6 |
|---|---|
| Message-ID | <963621801C6D3E4A9CF454A1972AE8F506711E@server2000.arneill-py.sacramento.ca.us> |
Brian, > Brian E Carpenter wrote: > And people wonder why we say that state is evil, and > distributed state is more evil. No argument here. > I don't think we should design policy for > stateful firewalls. We don't have a choice. Network administrators want firewalls. Actually, they don't want firewalls, they WANT firewalls; they MUST HAVE a firewall. This is a requirement; even if there were no technical reasons to have one (and there are plenty of good ones) there is a hidden requirement that says that one MUST operate a box with "firewall" written on the front panel. I sometimes have a hard time explaining to some small customers that a Cisco router running the FW/IDS feature set correctly configured is a firewall because it's not labeled "firewall" on the front bezel. One pre-sales guy suggested one time that we buy Pix 515 front bezels and replace the 2600 bezels with them..... Now, if we could have stateless firewalls, I would not mind a bit. > I think we're drifting away from the question of what the policy > should say. The point, I think, was to ease the wording to allow > for giving /32s in any case where common sense would allow it. Or do nothing and keep the current system where RIRs make an exception and assign space based on their best judgment of common sense. Michel. _______________________________________________ global-v6 mailing list [email protected] http://mailman.apnic.net/mailman/listinfo/global-v6