Slashdot Mirror


Obsession With Firewalls Could Hinder IPv6

DosIgriegas writes "The obsession with firewalls in IPv6 may result in some of the quirks of IPv4 reappearing. Ars Technica has an article looking at the topic in depth, exploring the technical challenges of securing the new protocol, and looking a the re-emergence of old problems in new guises. 'Ironically, what's required to make IPv6 work through a stateful firewall is almost identical to what's required to make IPv4 work though NAT. This means the IETF's efforts to keep IPv6 NAT-free in order to make protocols do their job without messy workarounds are defeated by the notion that everything should be firewalled.' If we decide to stick with firewalls in IPv6, we'll see many of the same hard-to-diagnose network problems that we have with IPv4."

5 of 278 comments (clear)

  1. Transmission by eldavojohn · · Score: 4, Funny
    Request:

    Obsession With Firewalls Could Hinder IPv6
    *incoming request on port 9045, port reserved for new ideas*

    Response: 'Obsession'?! I don't know what you're talking about.

    *request identified as critical of host*
    *request forwarded to port 6666*
    *incoming request on port 6666, port reserved for criticism*


    Response: Maybe I'm not the problem, maybe IPv6 is the problem? Shouldn't a solution to a problematic situation meet the needs of said situation, not the other way around?

    *incoming request passed through network firewall, computer hardware firewall and finally rejected by software firewall, request complete*
    --
    Come on, this is like intercourse, sometimes girls/requests just require double or even triple bagging, the last thing you want is a virus. Some girls are regular port scanners ifyaknowwhatImean ...
    --
    My work here is dung.
    1. Re:Transmission by Anonymous Coward · · Score: 1, Funny

      http://thedailywtf.com/forums/55879/PostAttachment .aspx

      Caption says "Error fetching resource list from repository.

      Reason:
      I/O exception occured: Connection refused: I HATE YOU.

  2. In order to help technology progress by Timesprout · · Score: 4, Funny

    I hereby announce I am giving up my obsession with firewalls and reverting to my earlier obsession with Halle Berry.

    --
    Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
    What truth?
    There is no dupe
    1. Re:In order to help technology progress by archen · · Score: 2, Funny

      Then thank god that day will never come =)

  3. 128 bits by CrtxReavr · · Score: 5, Funny

    Since we have the attention of the IPv6 crowd, everyone should add this record to your forward zones:

    aacs IN AAAA 09f9:1102:9d74:e35b:d841:56c5:6356:88c0

    -CR

    --
    "So is the BSD licence even more 'free' (than GPLv2)? Yes. Unquestionably." --Linus Torvalds (TinyURL.com/2vugzl)