dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
6
share rss forum feed

JoelC707
Premium
join:2002-07-09
Lanett, AL
kudos:5
reply to whfsdude

Re: [IPv6] Seeing two different LAN side ranges

Ahhh ok that makes more sense

I do have ICMP enabled for v4 and v6. At the moment I dont have any services i want to open up on the lan for v6 (yet). If youre doing vlan or host based security then that makes more sense. I thought you were saying i needed to open up the network for general browsing over IPv6 to work, but that makes more sense.


whfsdude
Premium
join:2003-04-05
Washington, DC
Reviews:
·Comcast
said by JoelC707:

I do have ICMP enabled for v4 and v6. At the moment I dont have any services i want to open up on the lan for v6 (yet). If youre doing vlan or host based security then that makes more sense.

Yeah, when you're dealing with VLANs, you scoot the rules back to the VLAN interfaces (eg. LAN, Voice) because you don't want traffic passing between the VLANs without rules in place.

For this reason, I've always been taught it's best to put the firewall/ACL as close to the network you want to protect as possible.