From b9abc962d99f680255f698a7b722dde5e7b18526 Mon Sep 17 00:00:00 2001 From: Major Hayden Date: Wed, 7 Oct 2015 16:24:07 -0500 Subject: [PATCH] V-3854{8,9}, V-38553: IPv6 filtering/security Implements: blueprint security-hardening Change-Id: I1fcca68c70ce7953e9bf8dad79dce1eb3f5592bc --- doc/source/developer-notes/V-38548.rst | 4 ++++ doc/source/developer-notes/V-38549.rst | 6 ++++++ doc/source/developer-notes/V-38553.rst | 1 + 3 files changed, 11 insertions(+) create mode 100644 doc/source/developer-notes/V-38548.rst create mode 100644 doc/source/developer-notes/V-38549.rst create mode 120000 doc/source/developer-notes/V-38553.rst diff --git a/doc/source/developer-notes/V-38548.rst b/doc/source/developer-notes/V-38548.rst new file mode 100644 index 00000000..27b4567a --- /dev/null +++ b/doc/source/developer-notes/V-38548.rst @@ -0,0 +1,4 @@ +**Exception** + +Disabling IPv6 redirects can cause issues with OpenStack environments which +have IPv6 enabled and are routing IPv6 traffic. diff --git a/doc/source/developer-notes/V-38549.rst b/doc/source/developer-notes/V-38549.rst new file mode 100644 index 00000000..737ff656 --- /dev/null +++ b/doc/source/developer-notes/V-38549.rst @@ -0,0 +1,6 @@ +**Exception** + +Adding IPv6 firewalling on OpenStack hosts is left up to the deployer to +configure. Deployers are urged to use proper network segmentation between +their OpenStack infrastructure and virtual machines, which will mitigate +many of the most critical threats. diff --git a/doc/source/developer-notes/V-38553.rst b/doc/source/developer-notes/V-38553.rst new file mode 120000 index 00000000..7bef75f1 --- /dev/null +++ b/doc/source/developer-notes/V-38553.rst @@ -0,0 +1 @@ +V-38549.rst \ No newline at end of file