Netdev List
 help / color / mirror / Atom feed
* VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts
@ 2012-11-27 14:54 Fernando Gont
  2012-11-27 16:04 ` Eric Dumazet
  2012-11-27 16:10 ` Jan Engelhardt
  0 siblings, 2 replies; 12+ messages in thread
From: Fernando Gont @ 2012-11-27 14:54 UTC (permalink / raw)
  To: netdev

Folks,

FYI. This is might affect Linux users employing e.g. OpenVPN:
<http://tools.ietf.org/html/draft-gont-opsec-vpn-leakages>.

For a project such as OpenVPN, a (portable) fix might be non-trivial.
However, I guess Linux might hook some iptables rules when establishing
the VPN tunnel, such that e.g. all v6 traffic is filtered (yes, this is
certainly not the most desirable fix, but still probably better than
having your supposedly-secured traffic being sent in the clear).

P.S.: Not sure if this is the right list to send this note. Please
advice of a more appropriate one and/or feel free to forward this note
if deemed appropriate...

Thanks,
-- 
Fernando Gont
e-mail: fernando@gont.com.ar || fgont@si6networks.com
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2012-11-29  4:38 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-11-27 14:54 VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts Fernando Gont
2012-11-27 16:04 ` Eric Dumazet
2012-11-27 16:07   ` Fernando Gont
2012-11-27 16:22     ` Michal Kubeček
2012-11-27 16:10 ` Jan Engelhardt
2012-11-28 19:57   ` Fernando Gont
2012-11-28 20:06     ` Jan Engelhardt
2012-11-28 20:14       ` Fernando Gont
2012-11-28 21:37         ` Jan Engelhardt
2012-11-29  2:29           ` Fernando Gont
2012-11-29  3:15             ` Jan Engelhardt
2012-11-29  4:38               ` Fernando Gont

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox