logoalt Hacker News

mlangenbergyesterday at 7:07 PM3 repliesview on HN

> There are also still a lot of misconceptions from network administrators who are scared of or don’t properly understand IPv6

Enable IPv6 on a TP-Link Omada router (ER7212PC) and all internal services are exposed to the outside world as there is no default IPv6 deny-all rule and no IPv6 firewall. I get why some people are nervous.


Replies

jeroenhdyesterday at 10:51 PM

That's more proof that TP-Link should not be trusted than that there is a problem with IPv6, really. Even cheap $20 Aliexpress routers have a firewall enabled by default.

show 1 reply
gz09yesterday at 7:18 PM

I believe that was more a bug in the firmware that's been fixed for a while now.

show 2 replies
throw0101cyesterday at 8:01 PM

> Enable IPv6 on a TP-Link Omada router (ER7212PC) and all internal services are exposed to the outside world as there is no default IPv6 deny-all rule and no IPv6 firewall. I get why some people are nervous.

A router routing traffic makes people nervous? Isn't that what it's supposed to do? I'd be annoyed if my router did not pass traffic.

Now, if the ER7212PC was a firewall that would be something else.

(And no, I'm not being pedantic: routers should pass traffic unless told otherwise, firewalls should block traffic unless told otherwise. The purposes of the two device classes are different, they just happen to both deal with Layer 3 protocol data units.)

show 5 replies