27 Apr
2012
27 Apr
'12
10:39 a.m.
On 4/27/2012 9:26 AM, Chris Adams wrote:
I don't think that will work, because there's an automatic direct route for fe80::/64 to all interfaces with family inet6 configured. The only way I see around it is to apply a firewall filter to all IPv6 interfaces that blocks anything with a source in fe80::/64 and destination _not_ in fe80::/64.
fe80::/65 discard fe80:0:0:0:8000::/65 discard More specifics rule out over connected any day. Jack