Block IPv6 settings from within Policy Manager?

Hi!

 

Can't find to controll this setting from within Policy Manager. Where do I find it? Possible?

2018-08-09_14-21-33.png

Best Answer

  • RmBRmB Posts: 31
    Accepted Answer

    Hi,

     

    You can find that setting advanced view in PM.

    1. Choose correct machine or domain 

    2. Settings - Advanced view

    3. F-Secure Internet Shield-> Firewall Engine-> IPv6 Filtering mode 

    4. Change IPv6 Filtering mode -setting 

    5. Distribute policies

     

    That's it! :)

    VadLakshiorx

Comments

  • iorxiorx Posts: 3

    Thank you for the swift response. Thats the one.

     

    I started receiveing a lot of "IPv6 small data gram ..." on some client machines. Haven't isolated the cause yet, but may be related to tethering and iPhone. Better safe than sorry, so blocking IPv6 until I can figure out why this all of a sudden has shown up.

     

    Brgs,

  • MJ-perCompMJ-perComp Posts: 1,098 Superuser

    Blocking V6 on the client is quick but dirty. It is like having two doors (V4 and V6) and only one (v4) with a propper guard, because you don't want to pay that second guard as noone is using that V6-door anyway.

     

    Now eveyone finds out there is a second door (v6) and you decide to place a signpost "No Entry, No Exit".


    So either configure it propperly or disable V6 in networking. Otherwise you will run into more trouble sooner or later. Using an unconfigured IPV6 is like setting up a Windows domain on 169.xxx.xxx.xxx/8
    with no DNS or DHCP.

  • iorxiorx Posts: 3

    I second that.

    IPv6 is properly configured at the Office LAN and remote offices, but outside that you've lost control. I suspect that tethering and the cell provider has implemented IPv6 recently.

    I'm working on build proper rules for the IPv6 in F-Secure and will test to release the total IPv6 block when done with that.

This discussion has been closed.