On Thu, 01 Sep 2016 16:47:23 +0200
shraptor <shrap...@bahnhof.se> wrote:

> I want to ask florian here why he disables IPv6 by blacklisting the
> IPv6 kernel module?


Hallo Shraptor,

I have an ip4 uplink and don't need ip6 atm, so I disable it (on all my
machines in the LAN). I call this "minimalism" ;) 

Blacklisting the kernel module is IMHO the easiest and besides setting
the kernel parameter in /etc/default/grub the only reliable way: IIRC,
disabling it in sysctl.conf disabled ip6 but didn't survive a reboot
without explicitly running 'sysctl -p' again, e.g. from /etc/rc.local.

> any security considerations? 

Definitely. I read quite thoroughly into the ip6 standard and found
that there's /a lot/ of complexity in it and its implementation. As
long as I don't need it, I wait for the dust to settle and at least
/some/ hidden bugs and other creepers to appear...

Libre Grüße,

Florian

_______________________________________________
Dng mailing list
Dng@lists.dyne.org
https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng

Reply via email to