#ident "@(#)issues 1.3 09/08/19 SAC" PSARC/2009/436 Anti-spoofing Link Protection Inception 08/19/2009 gw-1 What's the administrative interface? dladm? What's the policy for setting these properties? Near the end, what does PERM rw mean? gw-2 Is the cred of the caller available at the place where packets are dropped (and the statistics kept)? Would it make sense to generate audit records for drops? (There's likely to be future Audit work to alarm for certain configured threats that these records could feed into.) seb-01 The wording in the spec implies that all link-local addresses are implicitly included in allowed-ips. That doesn't seem right to me. That would imply that a zone can forge any source link-local address they wish... Do you instead mean _the_ link local address that is formed using an EUI-64 interface ID based on the link's MAC address? This must be what you meant to say, and it didn't accross well in the wording... seb-02 Are there cases where you want to let IPv4 packets with an unspecified source through? The spec doesn't appear to address that. seb-03 Do you verify that SLLA options in ICMPv6 packets match the MAC address of the link?