WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] IPV4 is nearly depleted, are you ready for IPV6?

To: rudi@xxxxxxxxxxx, Xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] IPV4 is nearly depleted, are you ready for IPV6?
From: Jonathan Tripathy <jonnyt@xxxxxxxxxxx>
Date: Mon, 06 Dec 2010 16:41:04 +0000
Cc:
Delivery-date: Mon, 06 Dec 2010 08:43:21 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <AANLkTikJsOP7_679y1aReZCMWcGpmCgmr8x4wgg09Zz8@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <AANLkTikJsOP7_679y1aReZCMWcGpmCgmr8x4wgg09Zz8@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.12) Gecko/20101027 Thunderbird/3.1.6

On 05/12/10 11:50, Rudi Ahlers wrote:
Seeing as IPV4 is near it's end of life
(http://www.internetnews.com/infra/article.php/3915471/IPv4+Nearing+Final+Days.htm),
I'm curios as who know whether everyone is ready for the changeover to
IPV6?

Is anyone using it in production already, and what are your experiences with it?

A problem with using IPv6 at the minute is that netfilter doesn't have as-advanced filtering capabilities as it does with IPv4. This is important when your DomUs are for customers on an unmanaged basis.

The main issue is that IPv6 doesn't use ARP anymore, so all MAC address detection is done in the IP layer and AFAIK, netfilter doesn't have the proper filtering for IPv6 to prevent MAC spoofing. What we really need is an IPv6 equivalent to arptables.

Cheers

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users