From owner-freebsd-net@FreeBSD.ORG Sat Jan 7 02:08:51 2012 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 695A5106566C for ; Sat, 7 Jan 2012 02:08:51 +0000 (UTC) (envelope-from prabhakar.lakhera@gmail.com) Received: from mail-yw0-f54.google.com (mail-yw0-f54.google.com [209.85.213.54]) by mx1.freebsd.org (Postfix) with ESMTP id 2F1158FC13 for ; Sat, 7 Jan 2012 02:08:50 +0000 (UTC) Received: by yhjj52 with SMTP id j52so28760yhj.13 for ; Fri, 06 Jan 2012 18:08:50 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; bh=NbDZNfSXgokfXIJqjJmmIR0eko3NKF2DeBO87OtxLIc=; b=bDLh63lSgCbY0WiDVUVQ19a5pqHhU2fcYJU4qA7Vy0cLrt4mMPhKu1K/SOCmRpqg9o SZ4+tdI7vW25JL7J1udwr6bzRQX9K3QMsJE+aPog4KH7eM+40kH2X8FC2Pgz+ZywjKxD oa8DSkzSi89V/zT0JZFyX25fKF055oVN5fdnA= MIME-Version: 1.0 Received: by 10.236.190.202 with SMTP id e50mr10789800yhn.91.1325900506483; Fri, 06 Jan 2012 17:41:46 -0800 (PST) Received: by 10.101.14.13 with HTTP; Fri, 6 Jan 2012 17:41:46 -0800 (PST) Date: Fri, 6 Jan 2012 17:41:46 -0800 Message-ID: From: prabhakar lakhera To: freebsd-net@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Subject: Ipv6 gw address scope limited by redirect? X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 07 Jan 2012 02:08:51 -0000 Hi, The RFC 4861 (ND) states the following for the icmpv6 redirect: Source Address MUST be the link-local address assigned to the interface from which this message is sent. This combined with the following in icmp6_redirect_input ensures that if a static default route was installed with non-LLA scoped gw the redirect sent by the router will go waste. if (bcmp(&src6, gw6, sizeof(struct in6_addr)) != 0) { 2354 nd6log((LOG_ERR, 2355 "ICMP6 redirect rejected; " 2356 "not equal to gw-for-src=%s (must be same): " 2357 "%s\n", 2358 ip6_sprintf(ip6buf, gw6), 2359 icmp6_redirect_diag(&src6, &reddst6, &redtgt6))); 2360 RTFREE_LOCKED(rt); 2361 goto bad; 2362 } Does it mean that if we want to be concerned with redirects we should ensure only LLA is given as the gw in the indirect routes? Best, Prabhakar