Re: [j-nsp] IPv6 firewall policy for MX

2019-06-29 Thread Lee Pedder
> > > > > I think you need to take some time to understand IPv6 before > implementing. > > The book examples don't restrict RS/RA to link local, are too open on > > things like BGP and traceroute. Trio hardware also has payload-protocol > > available in addition to next-header for matching. > > I

Re: [j-nsp] IPv6 firewall policy for MX

2019-06-29 Thread Saku Ytti
Hey Lee, > I think you need to take some time to understand IPv6 before implementing. > The book examples don't restrict RS/RA to link local, are too open on > things like BGP and traceroute. Trio hardware also has payload-protocol > available in addition to next-header for matching. I don't

Re: [j-nsp] IPv6 firewall policy for MX

2019-06-28 Thread Lee Pedder
It's a good start but there are many issues with it. I think you need to take some time to understand IPv6 before implementing. The book examples don't restrict RS/RA to link local, are too open on things like BGP and traceroute. Trio hardware also has payload-protocol available in addition to

Re: [j-nsp] IPv6 firewall policy for MX

2019-06-28 Thread Aaron Gould
2nd edition page 332 "IPv6 RE Protection Filter" -Aaron ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] IPv6 firewall policy for MX

2019-06-28 Thread Sander Steffann
Hi, > Is there a good online resource for IPv6 firewall policy/hardening for MX > series routers? I would start with the IPv6 filter example starting on page 336 of Juniper MX Series, 2nd Edition (ISBN: 978-1-4919-3272-8). There are eBook versions available, and o'Reilly Safari gives you

[j-nsp] IPv6 firewall policy for MX

2019-06-28 Thread Jonathan Call
Is there a good online resource for IPv6 firewall policy/hardening for MX series routers? ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp