local.m4: Untrusted source addresses appear on the backbone.
authorMark Wooding <mdw@distorted.org.uk>
Mon, 23 Apr 2012 00:20:28 +0000 (01:20 +0100)
committerMark Wooding <mdw@distorted.org.uk>
Mon, 23 Apr 2012 00:20:28 +0000 (01:20 +0100)
This happens because of router redundancy.  Case in point: suppose
vampire is selected via IPv6 router discovery, but radius owns the
external tunnel.  Then vampire will forward the packet over the
backbone to radius, which mustn't reject it.

(This isn't a security problem because the untrusted network isn't (by
definition) trusted very much for anything.


No differences found