3 ms·
> if you forget to also configure ip6tables Yeah, I've never understood that. I get that ping and traceroute have their own IPv6 versions, but that's sort of
by Nick_C 13y ago
> if you forget to also configure ip6tables
Yeah, I've never understood that. I get that ping and traceroute have their own IPv6 versions, but that's sort of understandable (maybe).
A firewall, though, is a firewall, it shouldn't matter what one of the IP protocols is. TCP and UDP don't have separate tools. The maintainers should clean it all up and put it into one iptables tool. If you want only IPv4, use a -4 flag, and ditto for IPv6 with a -6 flag. Heck, for most rules you can just imply it by the nature of the src and dst addresses.
- deleted 13y ago[deleted]
- noselasd 13y agoIt's because most firewall rules we deploy are for a combination of layer 3 and layer 4 addresses, not just layer 4(port numbers). And since layer 3 addresses are different between IP versions, we need different rules. (There may also be additional concerns if you enable V4 mapped addresses for IPv6)