if_stf and rfc1918

From: Lukasz Stelmach (Lukasz.Stelmach_at_telmark.waw.pl)
Date: 01/31/05

  • Next message: wsk: "DSL problem:PPPoE Pap Input: FAILURE ()"
    Date: Mon, 31 Jan 2005 00:53:57 +0100
    To: freebsd-net@freebsd.org
    
    
    

    Greetings All.

    Once I've discussed this matter with Hajimu UMEMOTO and he posted a patch
    that made it possible to run 6to4 router behind a nat (FreeBSD 4.x). Soon
    I will probably be upgrading my old system to 5.x release so I checked
    if newer stf code allows such operation and to my disapointment I've
    found out that it doesn't (or at least it seems so). The comment in the
    code says that it is a requirement of RFC3056. I've check it and in fact
    it says that RFC1918 addresses MUST NOT be used as NLAs in 6to4 addresses.
    But IMHO it does not mean that I can't run my 6to4 router behind a NAT
    at all. In such a situation the IPv6 address contains valid public IPv4
    address and the private one in the IPv4 header is substitutet by NAT. So
    after the packets leave my site they are completly valid 6to4 packets.
    Also when 6to4 packets come to me they are handeled properly.

    My question now is why FreeBSD is so restrictive about it.

    Best regards,
    Łukasz Stelmach.

    PS. Please cc: the answer, thank you.

    -- 
    |/       |_,  _   .-  --,  Już z każdej strony pełzną, potworne żądze
    |__ |_|. | \ |_|. ._' /_.         Będę uprawiał nierząd, za pieniądze
    
    



  • Next message: wsk: "DSL problem:PPPoE Pap Input: FAILURE ()"

    Relevant Pages

    • Re: Linksys WRT54G and Firewall software
      ... and it is completely unprotected on the LAN side. ... But what I have meant is that a average router is a very vulnerable ... NAT router's are not "secured" per se by default. ... NAT tries to match incoming packets to established connections and conversations. ...
      (comp.security.firewalls)
    • Re: ntpd fails to synchronize on FreeBSD 6.3-STABLE
      ... But please note that I shall install FreeBSD 7.0-RELEASE this weekend. ... Secondly I'm sorry for confusing you (NAT: I mean the machine ``behind NAT.'') ... to address is why your ntpd is failing to generate any IPv6 packets. ... configuration which works correctly with NTP on IPv4. ...
      (freebsd-stable)
    • Re: Just want to keep the crap out!!
      ... But then it's not a NAT router. ... address in packets coming from outside. ... First line: Home-built linux firewall ...
      (comp.security.firewalls)
    • Re: Circumventing NAT?
      ... > router with NAT. ... If a host had an address of 192.168.0.17 behind a router ... using source routed packets. ... a sensible firewall configuration should defeat these approaches. ...
      (alt.computer.security)
    • Re: nat problem
      ... to ensure that packets were using the router on which your NAT and route-map were configured. ... I made a new trace with wireshark (still for just one ping, ... then the packet is being dropped before or after NAT. ...
      (comp.dcom.sys.cisco)