From: Mark Wooding Date: Mon, 23 Apr 2012 00:20:28 +0000 (+0100) Subject: local.m4: Untrusted source addresses appear on the backbone. X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/commitdiff_plain/c353339c5f8e4afececd952fbebb09109b55dca1?hp=c353339c5f8e4afececd952fbebb09109b55dca1 local.m4: Untrusted source addresses appear on the backbone. This happens because of router redundancy. Case in point: suppose vampire is selected via IPv6 router discovery, but radius owns the external tunnel. Then vampire will forward the packet over the backbone to radius, which mustn't reject it. (This isn't a security problem because the untrusted network isn't (by definition) trusted very much for anything. ---