nanog mailing list archives
Re: SRv6 Capable NOS and Devices
From: Randy Bush <randy () psg com>
Date: Wed, 12 Jan 2022 13:52:24 -0800
What worries me more is the opportunity for adversaries to inject SRv6 packets. MPLS is not enabled by default on most router interfaces, so an adversary would have to have access to an interface where MPLS processing is explicitly enabled. IPv6 packet processing on the other hand… Unless an operator has airtight protection on every interface to block unwanted SRv6 headers I see some interesting opportunities to cause havoc :)
this is quite true, and a serious issue. but it has a good side. if you run an ipv6 enebled network, you can deploy srv6 without enabling srv6 everywhere, only at the marking encaps or embed) points. nice for partial and/or incremental deployment. randy, with no dog in this fight
Current thread:
- Re: SRv6 Capable NOS and Devices, (continued)
- Re: SRv6 Capable NOS and Devices Vincent Bernat (Jan 11)
- Re: SRv6 Capable NOS and Devices Saku Ytti (Jan 11)
- Re: SRv6 Capable NOS and Devices Mark Tinka (Jan 11)
- RE: SRv6 Capable NOS and Devices Adam Thompson (Jan 11)
- Re: SRv6 Capable NOS and Devices Mark Tinka (Jan 11)
- Re: SRv6 Capable NOS and Devices Saku Ytti (Jan 12)
- RE: SRv6 Capable NOS and Devices aaron1 (Jan 12)
- Re: SRv6 Capable NOS and Devices Saku Ytti (Jan 12)
- Re: SRv6 Capable NOS and Devices Sander Steffann (Jan 12)
- Re: SRv6 Capable NOS and Devices Dale W. Carder (Jan 12)
- Re: SRv6 Capable NOS and Devices Randy Bush (Jan 12)
- Re: SRv6 Capable NOS and Devices Sander Steffann (Jan 12)
- Re: SRv6 Capable NOS and Devices Colton Conor (Jan 12)
- Re: SRv6 Capable NOS and Devices Mark Tinka (Jan 12)
- Re: SRv6 Capable NOS and Devices Saku Ytti (Jan 13)
- Re: SRv6 Capable NOS and Devices Colton Conor (Jan 15)
- Re: SRv6 Capable NOS and Devices -> MPLS instead? Raymond Burkholder (Jan 15)
- Re: SRv6 Capable NOS and Devices -> MPLS instead? Mark Tinka (Jan 15)
- Re: SRv6 Capable NOS and Devices -> MPLS instead? scott (Jan 15)
- Re: SRv6 Capable NOS and Devices Mark Tinka (Jan 15)