Security Implications of IPv6 Fragmentation with IPv6 Neighbor Discovery
RFC 6980, “Security Implications of IPv6 Fragmentation with IPv6 Neighbor Discovery”, is a Proposed Standard document published in August 2013 by F. Gont. It updates RFC 3971, RFC 4861. The canonical text is published by the RFC Editor.
Abstract
This document analyzes the security implications of employing IPv6 fragmentation with Neighbor Discovery (ND) messages. It updates RFC 4861 such that use of the IPv6 Fragmentation Header is forbidden in all Neighbor Discovery messages, thus allowing for simple and effective countermeasures for Neighbor Discovery attacks. Finally, it discusses the security implications of using IPv6 fragmentation with SEcure Neighbor Discovery (SEND) and formally updates RFC 3971 to provide advice regarding how the aforementioned security implications can be mitigated.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6980 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6979 Deterministic Usage of the Digital Signature Algorithm and Elliptic Curve Digital Signature Algorithm
- RFC 6981 A Framework for IP and MPLS Fast Reroute Using Not-Via Addresses
- RFC 6978 A TCP Authentication Option Extension for NAT Traversal
- RFC 6982 Improving Awareness of Running Code: The Implementation Status Section
- RFC 6977 Triggering DHCPv6 Reconfiguration from Relay Agents
- RFC 6983 Models for HTTP-Adaptive-Streaming-Aware Content Distribution Network Interconnection
- RFC 6976 Framework for Loop-Free Convergence Using the Ordered Forwarding Information Base Approach
- RFC 6984 Interoperability Report for Forwarding and Control Element Separation