Hence, I don't think the routing-loop attack prevention is a
justification
for the "IID-format constraint".
I also wish it would not have been a justification, but for the
reason above I believe it is one we have to live with :-(.
Did I miss anything?
Regards,
RD
For a brief illustration of one instance of the the attack, here
is an
example:
+-------------------------------------------------------+
| IPv6 IPv6 packet |
|Internet dst6: 2002:198.16.9.9::1 |
| src6: 2001:db8:1::200:5efe:192.88.99.1|
| | |
| V |
| .--------------->--------------. | |
| / \| |
+--------+----------------------------------+-----------+
| |
2001:db8:1::/48 2002::/16
+---------+ +---------+
| ISATAP | | 6to4 |
+---------+ +---------+
198.16.9.9 192.88.99.1
| |
+--------+---------+ |
| IPv4 ^ | |
| site ^ | |
| ^ | V
| ^ | |
+--------+---------+ |
198.16.9.0/24 |
| |
| |
+--------+----------------------------------+-----------+
| IPv4 \ / |
|internet '----------------<-------------' |
| IPv6 in IPv4 packet |
| dst4: 198.16.9.9 |
| src4: 192.88.99.1 |
| |
+--------+----------------------------------+-----------+