On Jul 12, 2011 2:33 PM, "Tom Ammon" <tom.ammon@utah.edu> wrote:
Hi All,
We're pushing to get IPv6 deployed and working everywhere in our
operation, and I had some questions about best practices for a few things.
On your management nets (network device management nets) , what's the best
approach for addressing them? Do you use ULA? Or do you use global addresses and just depend on router ACLs to protect things? How close are we to having a central registry for unique local addresses, and will that really happen?
ACL are prone to typos and inconsistent deployment. If the security policy is that a give interface must not talk to the internet, ULA is a good choice as part of a multi-layer security strategy Cb
Tom
-----------------------------------------------------------------------------
Tom Ammon Network Engineer M: (801)674-9273 tom.ammon@utah.edu
Center for High Performance Computing University of Utah http://www.chpc.utah.edu
-----------------------------------------------------------------------------