Subject: Re: NFS over IPv6
To: Wolfgang Rupprecht <wolfgang@wsrcc.com>
From: Jason R Thorpe <thorpej@zembu.com>
List: tech-net
Date: 02/18/2001 11:04:37
On Sun, Feb 18, 2001 at 10:12:50AM -0800, Wolfgang Rupprecht wrote:

 > So how do you protect the v6 daemons?  (Other than by source IP
 > address only, which I don't really feel comfortable doing.)
 > 
 > I can't figure out how to get ipfilter to "block all" and only allow
 > certain v6 ports in.  It works fine for normal v4.  Tunneled v6
 > packets are a bit more challenging...

I dealt with this by writing my own IPv6-capable firewall package,
based on the BPF VM.

-- 
        -- Jason R. Thorpe <thorpej@zembu.com>