Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IPv6 doesn't mean everything has to be globally reachable (except for certain ICMP messages that should always work). By default, I think blocking general inbound traffic is the right way.

When you want to run a service (i.e. something peer to peer or a web server or something), there are protocols for applications to tell the firewall to open certain ports, such as PCP - http://en.wikipedia.org/wiki/Port_Control_Protocol



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: