OpenBSD does SLAAC with variable prefix length now. It doesn't have to
be /64, it can also be /60 or /68 for example.
note to whom breaks /64 will be blacklisted at spamhaus
there rule is /64 is a single user, /63 or less will be multispammers
OpenBSD does SLAAC with variable prefix length now. It doesn't have to
be /64, it can also be /60 or /68 for example.
Hello Markus,
On Sunday March 18 2018 11:41, you wrote to All:
OpenBSD does SLAAC with variable prefix length now. It doesn't have to be /64, it can also be /60 or /68 for example.
I have mixed feelings about this.
+ It allows more flexibility. For example if your ISP just gives you
one /64, you can still have multiple subnets. E.g by cutting the
/64 in 65536 /80s. Should be enough for everyone.
- The providers can use this as an argument to just give you one /64.
I think there was some ndp exhaustion attack where you were advised
to use something like /120 for link nets (not using SLAAC there of course) in order for routers to not have to keep huge NDP tables for
that link, so in that sense most software should be able to think in smaller than /64 nets and now, also for dynamic client configuration
on obsd.
Hello Janne!
The ND exhaustion attack would be only possible for a directly connected network, e.g. a LAN. A xfer network for a link between routers isn't
affected because ND should only accept local packets. Anyway, there are several solutions to limit/mitigate the problem for a LAN router.
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495938:47:19 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,963 |