From: James Ventre (messageboard@ventrefamily.com)
Date: Wed Dec 14 2005 - 13:51:31 GMT-3
IPv4 has mobility too: RFC3344
http://www.ietf.org/html.charters/mip4-charter.html
James
David Prall wrote:
> IPv6 with end-to-end IPSec has the same issues that IPv4 has with this. It
> requires a PKI infrastructure to properly support it. Once it is
> implemented, I can now transfer my virus without IDS/IPS being able to look
> into it. So now I have to have Host Based IDS/IPS to look into everything as
> well. NAT being a security tool isn't all that compelling when I can send an
> email to an end-user, they open that email and it goes out connects to a web
> server, run a java or activex applet and tell me that they are using an
> RFC-1918 address, yet my web server can tell that they are being NAT'd to
> such and such address. Using end-to-end IPv6 addresses requires the same
> security as IPv4. IPv6 adds things like mobility, which truly scares
> security people.
>
> David
>
> --
> David C Prall dcp@dcptech.com http://dcp.dcptech.com
This archive was generated by hypermail 2.1.4 : Mon Jan 09 2006 - 07:07:51 GMT-3