summaryrefslogtreecommitdiff
path: root/net/netfilter/nft_masq.c
diff options
context:
space:
mode:
authorErik Nordmark <nordmark@arista.com>2016-12-03 01:00:08 +0300
committerDavid S. Miller <davem@davemloft.net>2016-12-04 07:21:37 +0300
commitadc176c5472214971d77c1a61c83db9b01e9cdc7 (patch)
tree3eec6bc43480aac7ef49ac829c8da68028eebcdb /net/netfilter/nft_masq.c
parentce84c7c6637af66d6e6e11a54b2367fc8f1d7074 (diff)
downloadlinux-adc176c5472214971d77c1a61c83db9b01e9cdc7.tar.xz
ipv6 addrconf: Implemented enhanced DAD (RFC7527)
Implemented RFC7527 Enhanced DAD. IPv6 duplicate address detection can fail if there is some temporary loopback of Ethernet frames. RFC7527 solves this by including a random nonce in the NS messages used for DAD, and if an NS is received with the same nonce it is assumed to be a looped back DAD probe and is ignored. RFC7527 is enabled by default. Can be disabled by setting both of conf/{all,interface}/enhanced_dad to zero. Signed-off-by: Erik Nordmark <nordmark@arista.com> Signed-off-by: Bob Gilligan <gilligan@arista.com> Reviewed-by: Hannes Frederic Sowa <hannes@stressinduktion.org> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/netfilter/nft_masq.c')
0 files changed, 0 insertions, 0 deletions