Martin Millnert | 1 Sep 2011 09:58
Picon

Re: Adding IPv6 to Remote Access VPNs

Dyonisius,

On Mon, 2011-08-15 at 22:56 +0200, Dyonisius Visser wrote:
> AFAIK it is not possible (yet!) to use IPv6 as transport, but that is
> only a problem in IPv6-only access networks, which at the moment are
> very rare. In any way, my users have not yet found one to connect home
> from.

Expect this to change soon.  IPv6-only networks already exist, today,
and already affect various SP:s who can't deliver and thus by extension
all hw & sw providers.

At some point in the future you'll be well-served and praise yourself
for that list you made when you went almost-dual-stack, listing where
the (real) trouble to IPv6-only lies in your infrastructure, I think.

Regards,
Martin

Martin Millnert | 1 Sep 2011 09:58
Picon

Re: 6to4 disabled by default on W7SP1

On Thu, 2011-08-25 at 22:12 +0100, Nick Hilliard wrote:
> In this case not - it was a virgin installation of W7SP1 Enterprise which I
> had just downloaded from the Microsoft volume licensing site.  Teredo and
> ISATAP interfaces appeared after installation, but not 6to4.  Not sure why,
> but there you go.
> 

Sounds to me like you should file a bug-report, then. :-)

/M

Jeroen Massar | 1 Sep 2011 10:20
Favicon
Gravatar

Re: 6to4 disabled by default on W7SP1

On 2011-09-01 09:58 , Martin Millnert wrote:
> On Thu, 2011-08-25 at 22:12 +0100, Nick Hilliard wrote:
>> In this case not - it was a virgin installation of W7SP1 Enterprise which I
>> had just downloaded from the Microsoft volume licensing site.  Teredo and
>> ISATAP interfaces appeared after installation, but not 6to4.  Not sure why,
>> but there you go.
>>
> 
> Sounds to me like you should file a bug-report, then. :-)

Nick, as it is Volume Licensing, did you maybe make it part of a Active
Directory domain? As the rules for what are enabled then are changed a
bit afaik per default already, eg disabling tunneling methods as
generally these are not wanted in a corporate environment, and of course
the AD can force these settings upon clients too.

Greets,
 Jeroen

Nick Hilliard | 1 Sep 2011 10:44
Favicon

Re: 6to4 disabled by default on W7SP1

On 01/09/2011 09:20, Jeroen Massar wrote:
> Nick, as it is Volume Licensing, did you maybe make it part of a Active
> Directory domain?

nope, standalone installation.

Nick

Phil Mayers | 1 Sep 2011 13:51
Picon

Re: 6to4 disabled by default on W7SP1

On 01/09/11 09:20, Jeroen Massar wrote:
> On 2011-09-01 09:58 , Martin Millnert wrote:
>> On Thu, 2011-08-25 at 22:12 +0100, Nick Hilliard wrote:
>>> In this case not - it was a virgin installation of W7SP1 Enterprise which I
>>> had just downloaded from the Microsoft volume licensing site.  Teredo and
>>> ISATAP interfaces appeared after installation, but not 6to4.  Not sure why,
>>> but there you go.
>>>
>>
>> Sounds to me like you should file a bug-report, then. :-)
>
> Nick, as it is Volume Licensing, did you maybe make it part of a Active
> Directory domain? As the rules for what are enabled then are changed a
> bit afaik per default already, eg disabling tunneling methods as
> generally these are not wanted in a corporate environment, and of course
> the AD can force these settings upon clients too.

This was my impression until recently too; I thought that, by default, 
AD members with "client" role had 6to4 disabled, with Teredo and ISATAP 
enabled.

However, I've recently concluded this must be untrue or incomplete, 
based on observations at our site.

Can anyone state with confidence what the default behaviour matrix is?

Cheers,
Phil

(Continue reading)

Bernhard Schmidt | 1 Sep 2011 14:26
Picon

Re: 6to4 disabled by default on W7SP1

Hi,

> This was my impression until recently too; I thought that, by default,
> AD members with "client" role had 6to4 disabled, with Teredo and ISATAP
> enabled.

It's the other way around, Teredo is disabled in "Enterprise" clients, 
6to4 and ISATAP are enabled ("Enterprise" client meaning joined to an 
AD). You have to do specific configuration to enable Teredo in this 
environment.

Bernhard

Phil Mayers | 1 Sep 2011 15:57
Picon

Re: 6to4 disabled by default on W7SP1

On 01/09/11 13:26, Bernhard Schmidt wrote:
> Hi,
>
>> This was my impression until recently too; I thought that, by default,
>> AD members with "client" role had 6to4 disabled, with Teredo and ISATAP
>> enabled.
>
> It's the other way around, Teredo is disabled in "Enterprise" clients,
> 6to4 and ISATAP are enabled ("Enterprise" client meaning joined to an
> AD). You have to do specific configuration to enable Teredo in this
> environment.

Interesting. Is this documented somewhere or are you going on observation?

FYI we've recently explicitly disabled all 3 transition technologies 
(Teredo, 6to4, ISATAP) via group policy at our site. Confusingly, the 
output of "ipconfig /all" now shows:

6to4 adapter: completely absent from output
Teredo/ISATAP: show "Media disconnected"

...the latter of course not being very helpful at all.

Alec Edworthy | 1 Sep 2011 23:05
Picon
Favicon

Re: Lion + AnyConnect = b0rked IPv6

On 31 Aug 2011, at 16:22, Dyonisius (Dick) Visser wrote:
> That means my Lion upgrades and v6-only-Samba server will be stalled for
> at least 3 months :(

I'm very glad to be able to say that I've been speaking to one of my contacts within Cisco and it looks like
there should be a version containing the required fix out sometime in September.  I can't be more precise
than that at this stage but it's definitely better news than before.

Kind regards, Alec

--

-- 
Alec Edworthy
A.Edworthy <at> lboro.ac.uk

Dan Wing | 2 Sep 2011 01:44
Picon
Favicon

RE: 6to4 disabled by default on W7SP1

> -----Original Message-----
> From: ipv6-ops-bounces+dwing=cisco.com <at> lists.cluenet.de [mailto:ipv6-
> ops-bounces+dwing=cisco.com <at> lists.cluenet.de] On Behalf Of Phil Mayers
> Sent: Thursday, September 01, 2011 6:58 AM
> To: ipv6-ops <at> lists.cluenet.de
> Subject: Re: 6to4 disabled by default on W7SP1
> 
> On 01/09/11 13:26, Bernhard Schmidt wrote:
> > Hi,
> >
> >> This was my impression until recently too; I thought that, by
> default,
> >> AD members with "client" role had 6to4 disabled, with Teredo and
> ISATAP
> >> enabled.
> >
> > It's the other way around, Teredo is disabled in "Enterprise"
> clients,
> > 6to4 and ISATAP are enabled ("Enterprise" client meaning joined to an
> > AD). You have to do specific configuration to enable Teredo in this
> > environment.
> 
> Interesting. Is this documented somewhere or are you going on
> observation?
> 
> 
> FYI we've recently explicitly disabled all 3 transition technologies
> (Teredo, 6to4, ISATAP) via group policy at our site. Confusingly, the
> output of "ipconfig /all" now shows:
> 
(Continue reading)

Bernhard Schmidt | 2 Sep 2011 08:29
Picon

Re: 6to4 disabled by default on W7SP1

Am 01.09.2011 15:57, schrieb Phil Mayers:

Hi,

> On 01/09/11 13:26, Bernhard Schmidt wrote:
>> Hi,
>>
>>> This was my impression until recently too; I thought that, by default,
>>> AD members with "client" role had 6to4 disabled, with Teredo and ISATAP
>>> enabled.
>>
>> It's the other way around, Teredo is disabled in "Enterprise" clients,
>> 6to4 and ISATAP are enabled ("Enterprise" client meaning joined to an
>> AD). You have to do specific configuration to enable Teredo in this
>> environment.
>
> Interesting. Is this documented somewhere or are you going on observation?

Observation, but it appears I was wrong :-)

http://blogs.technet.com/b/edgeaccessblog/archive/2010/05/21/directaccess-and-teredo-adapter-behavior.aspx

[...]
Teredo Clients and Managed Networks

Now the celebrity question is “how does the DirectAccess client 
determine is there is a domain controller on the network?” That’s a 
great question, and it’s not easy to find an answer to it. At least it 
wasn’t easy, until this article was published.

(Continue reading)


Gmane