Re: [BEHAVE] How to set the DF and the ID values for IPv4 packets (was Re: Amount of fragmentation resulting from translation
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] How to set the DF and the ID values for IPv4 packets (was Re: Amount of fragmentation resulting from translation



On 30 okt 2009, at 19:45, marcelo bagnulo braun wrote:

The draft has section 8. Application scenarios which describe the scenarios that are defined in the framework document that the nat64 apply. Not sure if more is needed.
If you think it does, please propose text so that wg can comment.

A stateful NAT64 can be deployed anywhere wwhere there is a globally routable IPv4 address available for use by the translator and there is an IPv6 path towards the hosts that are served by the translator.

Secondary considerations are:

- paths with at least a 1500-byte MTU to both the IPv6 hosts served by the translator and the IPv4 internet are highly recommended

- the ability to provide the IPv6 hosts served by the translator with DNS resolver addresses that point to the DNS64 (through DHCPv6 or RFC 5006)

- the ability to restrict access to the IPv6 side of the translator by filtering addresses (i.e., if IPv6 source addresses can be spoofed the translator may be abused to hide attacks towards third parties)

Deployment within an ISP network or a reasonably sized enterprise network will easily accommodate all of the above. Deployment in a SOHO environment or across the public internet is not impossible, but does require compromises and/or extra complexity.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.