Hi Fernando,
On 06/10/2012 16:55, Fernando Gont wrote: > On 10/06/2012 03:49 PM, Brian E Carpenter wrote: >>> o Filter specific extension headers, where possible >> Please consider citing draft-carpenter-6man-ext-transmit, which discusses >> what firewalls need to do about extension headers. > > Wasn't aware about this I-D: > > 1) What's the plan for it? We've requested a slot in 6man at the Atlanta IETF. Obviously, if it moves forward, it will also need security review. > > 2) It should probably reference draft-ietf-6man-oversized-header-chain, > since it means that you can safely drop first-fragments that fail to > include the entire IPv6 header chain. I will note that for the next version, thanks. Brian > > Cheers, _______________________________________________ OPSEC mailing list [email protected] https://www.ietf.org/mailman/listinfo/opsec
