ufw

Comment 8 for bug 720605

Revision history for this message
Romain Boissat (rboissat) wrote :

Jamie: Yes, I just tested your diff applied against default before6.rules and it works, fixing the misbehavior I initially reported.

However, I find "-p icmpv6 --icmpv6-type echo-reply" too restrictive, as multicast traffic may right now and certainly will later imply other protocols than ICMPv6 (and especially other than EchoRequest and EchoReply messages). I don't have any particular application in mind right now, but I feel confident that multicast won't be only used to play with ping6 ;)

However, we may keep it restrictive right now and open it up later, according to new needs and new bug reports.

What do you think about this?