Teredo IPv6 tunnel through IPv4 - Any way to inspect without going to IPv6?
Hi All,
FortiGate 300D v5.4.1. Just going live with a subset of our vlans and watching traffic, I noticed a ton of UPD/3544 from our Windows boxes, which is likely Teredo - Microsoft's IPv6 tunnel through IPv4. I've kept everything in-house at IPv4 still.
A while back there were a lot of comments that Teredo could too easily be used by malware to bypass inspection by gateway firewalls. I haven't seen much recently, but Symantec's write up on it was concerning: http://www.symantec.com/avcenter/reference/Teredo_Security.pdf.
My uneducated questions:
- Is Teredo still seen as a security risk?
- I assume FGT isn't aware of Teredo and there's no way for me to inspect it without moving over to IPv6 dual stack?
- Has anybody blocked Teredo at the FGT and disabled for the Windows clients (netsh interface teredo set state disable) and how did it go?
Thanks in advance for any pointers.
