--- 1/draft-ietf-opsec-lla-only-09.txt 2014-07-28 01:14:48.558141280 -0700 +++ 2/draft-ietf-opsec-lla-only-10.txt 2014-07-28 01:14:48.582141871 -0700 @@ -1,18 +1,18 @@ OPsec Working Group M. Behringer Internet-Draft E. Vyncke Intended status: Informational Cisco -Expires: January 24, 2015 July 23, 2014 +Expires: January 29, 2015 July 28, 2014 Using Only Link-Local Addressing Inside an IPv6 Network - draft-ietf-opsec-lla-only-09 + draft-ietf-opsec-lla-only-10 Abstract In an IPv6 network it is possible to use only link-local addresses on infrastructure links between routers. This document discusses the advantages and disadvantages of this approach to help the decision process for a given network. Status of This Memo @@ -22,21 +22,21 @@ Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at http://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." - This Internet-Draft will expire on January 24, 2015. + This Internet-Draft will expire on January 29, 2015. Copyright Notice Copyright (c) 2014 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (http://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents @@ -72,24 +72,24 @@ of a router is also not reachable beyond the link boundaries, therefore reducing the attack horizon. This document discusses the advantages and caveats of this approach. Note that some traditionally used techniques to operate a network such as pinging interfaces, or seeing interface information in a traceroute do not work with this approach. Details are discussed below. - During IESG review the technical correctness and completeness of the - document has been fully reviewed and verified, However, IESG noted - that there was no full consensus within the working group on whether - to recommend this technique. + During WG and IETF last call the technical correctness of the + document has been reviewed, however debate exists as to whether to + recommend this technique. The deployment of this technique is + appropriate where it is found to be necessary. 2. Using Link-Local Addressing on Infrastructure Links This document discusses the approach of using only link-local addresses (LLA) on all router interfaces on infrastructure links. Routers don't typically need to receive packets from hosts or nodes outside the network. For a network operator, there may be reasons to use greater than link-local scope addresses on infrastructure interfaces for certain operational tasks, such as pings to an interface or traceroutes across the network. This document discusses