Presentation is loading. Please wait.

Presentation is loading. Please wait.

Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Administrators Mobile IPv6 Suresh Krishnan, Niklas Steinleitner, Ying Qiu, Gabor.

Similar presentations


Presentation on theme: "Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Administrators Mobile IPv6 Suresh Krishnan, Niklas Steinleitner, Ying Qiu, Gabor."— Presentation transcript:

1 Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Administrators Mobile IPv6 Suresh Krishnan, Niklas Steinleitner, Ying Qiu, Gabor Bajko mext@IETF70

2 Top right corner for field-mark, customer or partner logotypes. See Best practice for example. Slide title 40 pt Slide subtitle 24 pt Text 24 pt Bullets level 2-5 20 pt Suresh KrishnanMobile IPv6 Firewall Admin Recommendations2007-12-042 Introduction  Firewalls are not aware of MIPv6 protocol details –Hence they will interfere with the smooth operation of the protocol –Problems are documented in RFC4487  This document provides recommendations to administrators for adding static rules on firewalls –This allows certain classes of signaling messages to pass through the firewall, based only on policy  Depends on the existence of another document that specifies how to create state on the firewall –Open data pinholes based on the signaling packets

3 Top right corner for field-mark, customer or partner logotypes. See Best practice for example. Slide title 40 pt Slide subtitle 24 pt Text 24 pt Bullets level 2-5 20 pt Suresh KrishnanMobile IPv6 Firewall Admin Recommendations2007-12-043 Classification of recommendations  Recommendations are classified according to the target audience –Firewall protecting Home Agent –Firewall protecting Mobile Node –Firewall protecting Correspondent Node  Traffic that needs to pass through each of the above firewalls is listed  Traffic patterns are specified for each of these traffic types

4 Top right corner for field-mark, customer or partner logotypes. See Best practice for example. Slide title 40 pt Slide subtitle 24 pt Text 24 pt Bullets level 2-5 20 pt Suresh KrishnanMobile IPv6 Firewall Admin Recommendations2007-12-044 Security  Whether or not nodes in a network may receive unsolicited traffic is an administrative decision that is independent of MIPv6 –Allowing an incoming CoTI message is no more dangerous than allowing say a SIP invite –Firewalls need to check for malformed and malicious packets matching these filters  The firewalls MAY need to rate limit some of these traffic types to avoid DoS attacks

5 Top right corner for field-mark, customer or partner logotypes. See Best practice for example. Slide title 40 pt Slide subtitle 24 pt Text 24 pt Bullets level 2-5 20 pt Suresh KrishnanMobile IPv6 Firewall Admin Recommendations2007-12-045 Further steps  Questions?  Comments?  Adoption as WG document?


Download ppt "Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Administrators Mobile IPv6 Suresh Krishnan, Niklas Steinleitner, Ying Qiu, Gabor."

Similar presentations


Ads by Google