Recommendations for Filtering ICMPv6 Messages in Firewalls
RFC 4890, “Recommendations for Filtering ICMPv6 Messages in Firewalls”, is an Informational document published in May 2007 by E. Davies, J. Mohacsi. The canonical text is published by the RFC Editor.
Abstract
In networks supporting IPv6, the Internet Control Message Protocol version 6 (ICMPv6) plays a fundamental role with a large number of functions, and a correspondingly large number of message types and options. ICMPv6 is essential to the functioning of IPv6, but there are a number of security risks associated with uncontrolled forwarding of ICMPv6 messages. Filtering strategies designed for the corresponding protocol, ICMP, in IPv4 networks are not directly applicable, because these strategies are intended to accommodate a useful auxiliary protocol that may not be required for correct functioning.
This document provides some recommendations for ICMPv6 firewall filter configuration that will allow propagation of ICMPv6 messages that are needed to maintain the functioning of the network but drop messages that are potential security risks. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4890 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4889 Network Mobility Route Optimization Solution Space Analysis
- RFC 4891 Using IPsec to Secure IPv6-in-IPv4 Tunnels
- RFC 4888 Network Mobility Route Optimization Problem Statement
- RFC 4892 Requirements for a Mechanism Identifying a Name Server Instance
- RFC 4887 Network Mobility Home Network Models
- RFC 4893 BGP Support for Four-octet AS Number Space
- RFC 4886 Network Mobility Support Goals and Requirements
- RFC 4894 Use of Hash Algorithms in Internet Key Exchange and IPsec