A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operational Security Capabilities for IP
Network Infrastructure of the IETF.
Title : Recommendations on Filtering of IPv6 Packets
Containing IPv6 Extension Headers
Authors : Fernando Gont
Will(Shucheng) Liu
Ronald P. Bonica
Filename : draft-ietf-opsec-ipv6-eh-filtering-02.txt
Pages : 35
Date : 2016-10-31
Abstract:
It is common operator practice to mitigate security risks by
enforcing appropriate packet filtering. This document analyzes both
the general security implications of IPv6 Extension Headers and the
specific security implications of each Extension Header and Option
type. Additionally, it discusses the operational and
interoperability implications of discarding packets based on the IPv6
Extension Headers and IPv6 options they contain. Finally, it
provides advice on the filtering of such IPv6 packets at transit
routers, for those cases in which such filtering is deemed as
necessary.
The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsec-ipv6-eh-filtering/
There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-opsec-ipv6-eh-filtering-02
A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-ipv6-eh-filtering-02
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
_______________________________________________
OPSEC mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/opsec