SixXS::Sunset 2017-06-06

FAQ on firewalls/NAT
[us] Shadow Hawkins on Thursday, 01 April 2010 17:25:02
In the current [url=https://www.sixxs.net/faq/connectivity/?faq=firewalled]FAQ on firewalls/NAT[/url], it specifies that UDP 3740 (for heartbeat) need only be open for outgoing traffic. However, there is no similar qualification that outgoing traffic only need be open for UDP 5072 (AYIYA) nor TCP 3874 (TIC), although the text ambiguously implies ("no problem/no issue") that such is the case. Similarly, the entry for Protocol 41 (IPv6 over IPv4/6in4 tunnel) says that one "must" setup the tunnel recipient host as a DMZ host, whereas [url=https://www.sixxs.net/faq/connectivity/?faq=conntracking]elsewhere in the FAQ[/url] more specific/less inclusive firewall rules are prescribed. Can someone confirm that these specific firewall rules are indeed (and only) required: For all tunnels: TIC: TCP 3874 -- open outbound to TIC server (e.g tic.sixxs.net) only For static and dynamic/heartbeat tunnels: IPv6 over IPv4/6in4 tunnel: protocol 41-- open/forward/bypass-NAT inbound to tunnel host from PoP For dynamic/heartbeat tunnels: Heartbeat: UDP 3740 -- open outbound to PoP only For AYIYA tunnels: AYIYA: UDP 5072 -- open outbound to PoP only
FAQ on firewalls/NAT
[ch] Jeroen Massar SixXS Staff on Thursday, 01 April 2010 19:16:53
"Open Outbound" means that you need to be able to connect from your host crossing your firewall to that port on the machine indicated. Indeed there will be return traffic, but there will not be any connection initiated from the outside to the inside. TIC is only required if you actually use TIC, thus effectively if you are going to use AICCU. Heartbeat packets are only sent from the tunnel endpoint to the PoP. AYIYA packets are initiated from the tunnel endpoint to the PoP, which creates state in the NAT/firewall and thus traffic can flow in both directions. The reason for noting that most firewalls&NATs won't have an issue with AYIYA is because generally UDP is not being blocked and NAT boxes understand UDP (contrary to proto-41 which they don't understand). Note also that the last column is named 'NAT remarks'.

Please note Posting is only allowed when you are logged in.

Static Sunset Edition of SixXS
©2001-2017 SixXS - IPv6 Deployment & Tunnel Broker