[ndbug] PF question - is it reasonable to block all IPv6 traffic

N.J. Thomas njt at ayvali.org
Fri Dec 23 17:47:15 PST 2016


* Hrishikesh Murukkathampoondi <hrishim at gmail.com> [2016-12-23 19:00:46+0530]:
> If my machine has an IPv4 address only is it reasonable have pf block
> all traffic in and out?
> 
> # Block all IPV6 traffic
> block in quick inet6 all
> block out quick inet6 all

If you mean have pf block all IPv6 traffic, that's reasonable. If you
didn't have IPv6 setup to begin with, it won't make a difference in this
particular case, but it won't hurt either.

Thomas


More information about the talk mailing list