Jump to content
funtoo forums
Sign in to follow this  
nimbius

networking in containers needs a more sincere approach.

Recommended Posts

This is mostly a thread to endorse firewall and ipv6 as defacto elements of the container offering from Funtoo.  Among the reasons it should be considered:

 

Firewall:

1.  An internet presence without a firewall encourages abuse and is a poor practice that contributes to the harm of the internet and its users. 

2.  Firewalls can and should be used as a learning tool to help grow the understanding of Funtoo and Linux in general.  learning firewall implementation makes for a better user.

3.  iptables provides a wealth of other neat tools to help users learn basics and advanced concepts of networking such as masquerade and DPI. 

4.  the consequences of a breech far outweigh the repercussions of expanded conntrack overhead, whatever it may be.  a compromised container can put funtoo in RBL territory and reputation system blacklists.  our users deserve firewalls and freedom from the 'one rotten egg' type of bans on subnets enforced by google and cisco.

5.  its FUN to play in iptables http://shortround.net/2010/09/24/making-an-image-flip-proxy/

 

IPv6: 

1.  "Do IT" --S. LeBouf.

2.  ARIN insisted we have our collective ducks in a row in 2012.   Its had meaningful support in the kernel since 2006.  its support at the carrier level is ubiquitous.  most ISP's offer a v6 address, if not a subnet, for the user.

3.  nearly every hosting provider on earth supplies a v6 subnet to their customer.   If we continue treating IPv6 as an option and subject to interest, we tacitly imply a shortcoming in Funtoo. 

4.  ipv6 ipsec extensions are the security we need in 2016. modular headers, ndp, stateless and stateful configuration and host based routing isnt something thats going away.

5.  even your cellphone uses IPv6.  if you're a T-Mobile subscriber your stack to the tower is almost entirely v6.

6.  its fun to play with new things.  ipv6 load balancing is super neat.  developing new software that uses ipv6 means your container will have to support ipv6.

 

for containers to be competitive, attractive and useful, it means they have to support things that every other container supports.

Share this post


Link to post
Share on other sites
Guest
You are commenting as a guest. If you have an account, please sign in.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoticons maximum are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×