logoalt Hacker News

kstrauseryesterday at 4:00 AM1 replyview on HN

Different person here, but no. I never write firewall rules based on individual source addresses. They’re too easy to fake. And with IPv6’s privacy extensions, you never know what source address a given machine will have anyway.


Replies

gspryesterday at 8:49 AM

Interesting. How do you deal with destination addresses on your local network? DHCPv6 like the other poster and myself?