Hacker News new | ask | show | jobs
by dmatech 1008 days ago
You could, but now you have three addresses per node instead of one. Plus, the mechanisms for assigning those addresses are weird compared to DHCP and static assignment. I get that it facilitates packets being routed reliably, but some of us want maintainable firewall rules that don't have to deal with IP addresses changing out of the blue.
1 comments

You can DHCP or static assign those addresses the same. The trick to FW rules is you don't route the local prefix out so you only need rules for anything leaving or anything staying.

If you don't need cross subnet communication of your self hosted services you can also get away with just a static link-local and a dynamic general.