From: Bernd Eckenfels <be-mail2004@lina.inka.de>
To: linux-kernel@vger.kernel.org
Cc: Trent Lloyd <lathiat@bur.st>, 253590@bugs.debian.org
Subject: Re: Bug#253590: How to turn off IPV6 (link local)
Date: Tue, 15 Jun 2004 21:46:57 +0200 [thread overview]
Message-ID: <20040615194657.GA7474@lina.inka.de> (raw)
In-Reply-To: <20040615023022.GB24269@thump.bur.st>
On Tue, Jun 15, 2004 at 10:30:23AM +0800, Trent Lloyd wrote:
> >
> > net.ipv6.conf.default.autoconf does work for the received prefixes, but does
> > not avoid the link local configuration. (this is btw a documentation error)
>
> autoconf defines whether it will auto-configure an address if a router
> advertises the IPv6 prefix for the network to it.
Yes, but the configure help tells me otherwise. Especially since there are
two options (autoconfigure and accpet_ra) I dont think the current behavious
is intended:
autoconf - BOOLEAN
Configure link-local addresses using L2 hardware addresses.
Default: TRUE
accept_ra - BOOLEAN
Accept Router Advertisements; autoconfigure using them.
Functional default: enabled if local forwarding is disabled.
disabled if local forwarding is enabled.
So I think autoconf=0 should avoid adding the 3ff8 link local address (as
well as lo ::1)
> The issue is not having the link local address, because there is no
> default route and hence the connection should fail.
No, please check the bug report. The problem with netscape is that it _does_
fail and not fall back to ipv4. But I think for performance reasons, no ipv6
application should actually try to contact destinations which are not in
the scope of the configured address (dont connect to sitelocal/global of only
linklocal prefix is configured)
> The problem, in the case of thi sbug, is that he has IPv6 configured,
> but it is not working, 2001: is a real IPv6 address
That was the initial problem, but we have solved that by turning autoconf
off. The last email was only with an fe80:: prefix.
> Link-local address start with fe80:: and never have a default route so
> they will not be a problem.
They are the problem, as you see above because the applications still
prefers them over ipv4.
> You can't, but it is not the issue here, you could however not load the
> module.
Yes, if it is a module. But see my comment above, I dont think the sysctl
behaves as documented, and does not behave as expected.
I can prepare a patch for this, if everybody agrees. In addition to that, I
would like to know how application and resolver can be fixed to not use
incomplete or broken v6 setups (i.e. ignore link local prefix on non local
targets without trying to connect).
Greetings
Bernd
--
(OO) -- Bernd_Eckenfels@Mörscher_Strasse_8.76185Karlsruhe.de --
( .. ) ecki@{inka.de,linux.de,debian.org} http://www.eckes.org/
o--o 1024D/E383CD7E eckes@IRCNet v:+497211603874 f:+497211606754
(O____O) When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl!
next prev parent reply other threads:[~2004-06-15 19:47 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-06-14 23:32 Bernd Eckenfels
2004-06-15 2:30 ` Trent Lloyd
2004-06-15 19:46 ` Bernd Eckenfels [this message]
2004-06-15 21:27 ` Bug#253590: " Felipe Alfaro Solana
2004-06-15 22:58 ` Bernd Eckenfels
2004-06-16 0:16 ` Trent Lloyd
2004-06-16 1:17 ` Bernd Eckenfels
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040615194657.GA7474@lina.inka.de \
--to=be-mail2004@lina.inka.de \
--cc=253590@bugs.debian.org \
--cc=lathiat@bur.st \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®