On Thursday, May 08, 2014 12:51:05 PM Olivier Mascia wrote:

> Thanks for this advice.
> On the WAN interface, I’m currently allowing full ICMPv6
> in, albeit only from Global Unicast and Multicast
> addresses. That is: only from 2000::/3 and ff00::/8.

That's alright.

> Rate limits, at least on replies, *should* be inherent to
> the implementation of ICMPv6 as far as I have read
> (don’t remember where though). Is this enforced in
> pfSense, I don’t currently know.

I'm not sure the protocol implements any rate limiting, in 
the context of protecting your control plane.

Mark.

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
List mailing list
List@lists.pfsense.org
https://lists.pfsense.org/mailman/listinfo/list

Reply via email to