Community discussions

MikroTik App
 
AJSG1969
just joined
Topic Author
Posts: 5
Joined: Sun Oct 15, 2017 11:18 am

ipv6 6in4 ISATAP traffic block

Fri Feb 23, 2018 2:38 pm

I currently rely on a Pi-Hole enabled device to manage white/blacklists within the newtork. However ipv6 traffic seems to be very high and the Pi-Hole struggles to indentify it.

Is there a simple way at the router level to disable ipv6 tunnelling? Ii have read about 6in4 weaknesses and dangers and looking at the traffic it seems to be exclusively used by advertising sites/tag management/etc which escape the ipv4 whitelist in the Pi-Hole.

Thank you.

CCR1016
Current Firmware 3.27
RouterOS 6.41
WinBox
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: ipv6 6in4 ISATAP traffic block

Sat Feb 24, 2018 11:03 am

Hi

6in4 goes over protocol 41. If you don't want it, don't allow protocol41 over your routers.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: ipv6 6in4 ISATAP traffic block

Sat Feb 24, 2018 11:39 am

On the security aspect, which "weaknesses and dangers" are you referring too?
The dangers of 6in4, are same as in native ipv6: injection, spoofing, ... Nothing new here.

Please remember that 6to4 is a different thing than 6in4.

Who is online

Users browsing this forum: mquan1984 and 126 guests