3 ms·
> A router could auto-block an IPv6 address that's been in use too long, with a whitelist for servers. So… I’m not saying you don’t want to do that, but I do w
by labcomputer 2y ago
> A router could auto-block an IPv6 address that's been in use too long, with a whitelist for servers.
So… I’m not saying you don’t want to do that, but I do want to expand on this a bit:
4941 is not the only way to avoid having your MAC address in your IPv6 address. In fact RFC 3972 (from 2005! Almost old enough to buy beer!) describes a method for stable “cryptographic” addresses which enable the host to attest to the address’s authenticity in ND. That’s a really powerful feature because it means that another host can’t impersonate you like they can with ARP on v4. RFC 3972 is what macOS uses for the “non temporary” address (the one ifconfig labels “secured”). One of the things everyone should know about 3972 addresses is that a host will generate different addresses on different prefixes (so you can’t correlate a host moving between networks like you could with a MAC-derived address).
It is expected and normal that a host should have at least two “non temporary” addresses: a link local one, plus one generated by 3972 (or DHCPv6 or some other mechanism), in addition to one or more 4941 temporary addresses.
One way to block MAC-derived addresses without breaking e2e connectivity is to add a firewall rule blocking addresses with “FFFE” in the middle.