Reply to post: Re: This is a test of VPN technology; in 2015 "network" means IPv4 *and* IPv6.

VPNs are so insecure you might as well wear a KICK ME sign

Roland6 Silver badge

Re: This is a test of VPN technology; in 2015 "network" means IPv4 *and* IPv6.

Well the paper isn't totally clear (and it should be) about the test environment. It does seem that the test was of VPN over an IPv4 network, but details of the configuration (IPv4 and IPv6) are not obviously given.

What is not clear (from an initial skim reading) is whether the leakage is happening because of client dual stacks and hence IPv6 traffic is not being routed over the VPN or what. What is clear, from the paper, turning off the client IPv6 stack resolves the leakage problem, however it is noted that not all client OS's permit this.

I suspect from the article and my experience that this 'leakage' problem may not be wholly attributable to the specific protocol stacks being used, but to the mechanisms that are used to select between protocol stacks and specifically address the fundamental cause of the leakage "No rules are added to redirect IPv6 traffic into the tunnel.".

A paper now on the "to read" list.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon