Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers at Transit Routers
RFC 9288, “Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers at Transit Routers”, is an Informational document published in August 2022 by F. Gont, W. Liu. The canonical text is published by the RFC Editor.
Abstract
This document analyzes the security implications of IPv6 Extension Headers and associated IPv6 options. Additionally, it discusses the operational and interoperability implications of discarding packets based on the IPv6 Extension Headers and IPv6 options they contain. Finally, it provides advice on the filtering of such IPv6 packets at transit routers for traffic not directed to them, for those cases where such filtering is deemed as necessary.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9288 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9287 Greasing the QUIC Bit
- RFC 9289 Towards Remote Procedure Call Encryption by Default
- RFC 9286 Manifests for the Resource Public Key Infrastructure
- RFC 9290 Concise Problem Details for Constrained Application Protocol APIs
- RFC 9285 The Base45 Data Encoding
- RFC 9291 A YANG Network Data Model for Layer 2 VPNs
- RFC 9284 Multihoming Deployment Considerations for DDoS Open Threat Signaling
- RFC 9292 Binary Representation of HTTP Messages