Hacker Newsnew | past | comments | ask | show | jobs | submit | _bernd's commentslogin

This is really good and brief, but complete overview of the whole thing. Thanks for sharing.

The author has a long history of quality content and should be considered experienced in his field of doing.

You only need to set nothing and it should setup ipv6 on all downstream vlan interfaces. For static prefix I'd you can set ip6hint per vlan interface. For each vlan interface you need a stanza in the DHCP config file. And regarding firewall, as with the default lan zone you might need to add new zones with the vlan interfaces and configure forwarding rules. That's it.


Do you have heared of IP addresses and that large institutions especially government institutions have their own blocks from the address space? Mapping these is kind of easy.


They are likely behind (foreign) CDN's.

Not that there's no BYOIP and not that it's impossible to do with shared IP's


That's why server use a static suffix and do slaac to get their prefix. It's really as simple as that.

Regarding firewall policies:

just because most network OS are plain dumb, does not implies that's the fault of IPv6.

A zone based firewall solves that already. And for instance OpenWrt fw4 can make rules for suffixes in a zone too.


A path should be written `/root`...


You can also configure multiple CA for client auth, and on the client side multiple ca to verify host keys.


Tfa contains the whole session dude.


I will definitely start to read this out loud to my 5 year old. He will love it. Thanks for sharing your finding.


Just FYI. Almost every launcher that offers commercial services has such a user manual. I was involved in preparing one such manual. A collection of these manuals can be quite entertaining for 5 year olds. You should be able to easily find them from the websites of the respective companies or agencies.


Thanks for the tip. I only knew about old manuals of the space shuttle.



Have an LLM rewrite it in Seussian verse.


You can also sign ssh host keys with an ssh ca.

See ssh_config and ssh-keygen man-pages...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: