Re: [Shorewall-users] limiting IPv6 rule access to just next-hop, dynamic link-local address?

2015-08-11 Thread PGNet Dev
On 08/11/2015 01:08 AM, Simon Hobson wrote: > Unless I'm missing something, packets to/from link local addresses won't be > routed - and so should never go past the first hop. If that's the case -- makes sense, now that you mention, but worth a check -- then ACCEPT net:fe80::/10 $FW udp 546

Re: [Shorewall-users] limiting IPv6 rule access to just next-hop, dynamic link-local address?

2015-08-11 Thread Simon Hobson
pgnet@gmail.com wrote: > I've switched ISPs, and need to pull an IPv6 dhcp6-lease from the ISP > provided modem. > > To get the lease I opened > >ACCEPT net:fe80::::36df:cef3:332d2:aac1 $FW udp 546 > > where the [fe80::::36df:cef3:332d2:aac1] is the LinkLocal

[Shorewall-users] limiting IPv6 rule access to just next-hop, dynamic link-local address?

2015-08-10 Thread pgnet . dev
I've switched ISPs, and need to pull an IPv6 dhcp6-lease from the ISP provided modem. To get the lease I opened ACCEPT net:fe80::::36df:cef3:332d2:aac1 $FW udp 546 where the [fe80::::36df:cef3:332d2:aac1] is the LinkLocal address of the modem's internal interface