Subject: Re: NFS over IPv6
To: Wolfgang Rupprecht <wolfgang@wsrcc.com>
From: Jason R Thorpe <thorpej@zembu.com>
List: tech-net
Date: 02/18/2001 11:04:37
On Sun, Feb 18, 2001 at 10:12:50AM -0800, Wolfgang Rupprecht wrote:
> So how do you protect the v6 daemons? (Other than by source IP
> address only, which I don't really feel comfortable doing.)
>
> I can't figure out how to get ipfilter to "block all" and only allow
> certain v6 ports in. It works fine for normal v4. Tunneled v6
> packets are a bit more challenging...
I dealt with this by writing my own IPv6-capable firewall package,
based on the BPF VM.
--
-- Jason R. Thorpe <thorpej@zembu.com>