<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
Hi Pete,<br>
<br>
Thats re-assuring at least. Only just starting roll-out of IPv6
myself, all roll out has been done to managed devices thus far and I
hadn't entered the realm of Home CPE devices. If the major brands
have enough sense to include a basic set of filters then that is
music to my ears :).<br>
<br>
Thanks,<br>
Joe<br>
<br>
<div class="moz-cite-prefix">On 25/07/14 14:06, Pete Mundy wrote:<br>
</div>
<blockquote
cite="mid:323C61B6-C4AD-48D4-BF88-D71A00AF2655@fiberphone.co.nz"
type="cite">
<pre wrap="">On 25/07/2014, at 3:47 PM, Greg Anderson <a class="moz-txt-link-rfc2396E" href="mailto:ganderson@raywhite.com"><ganderson@raywhite.com></a> wrote:
</pre>
<blockquote type="cite">
<pre wrap="">I am not aware of any home router that out of the box has a firewall enabled for clients out of the box with IPv4. I generally expect that clients are (badly) protected because there is no NAT unless specified by an end user or UPNP. On many you can enable firewalls for the clients but they are usually for outbound traffic, or only inbound for a (usually single) DMZ type device that nearly all ports are forwarded to.
</pre>
</blockquote>
<pre wrap="">
I'm not sure if this is a type or what, but my experience is the exact opposite
I am not aware of any home router that out of the box does NOT have firewall enabled for IPv5 (nor NAT for that matter; for without it the user would have no internet on their multiple-device network with only one public v4 IP).
Furthermore, all IPv6 capable CPE devices that I've seen supplied by network providers here in NZ all have the IPv6 firewall enabled by default too. So you get real-world IP addresses on your workstations but they're protected at the border by default and you can't accept connections to them without loading a rule (ie no change from current situation with v4).
Pete
</pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
AusNOG mailing list
<a class="moz-txt-link-abbreviated" href="mailto:AusNOG@lists.ausnog.net">AusNOG@lists.ausnog.net</a>
<a class="moz-txt-link-freetext" href="http://lists.ausnog.net/mailman/listinfo/ausnog">http://lists.ausnog.net/mailman/listinfo/ausnog</a>
</pre>
</blockquote>
<br>
</body>
</html>