[GTER] Novo RFC 7123: Security Implications of IPv6 on IPv4 Networks

Henrique de Moraes Holschuh hmh at hmh.eng.br
Wed Feb 12 16:36:58 -02 2014


PSC:    http://tools.ietf.org/html/rfc7123

RFC 7123:
   Security Implications of IPv6 on IPv4 Networks

Abstract

   This document discusses the security implications of native IPv6
   support and IPv6 transition/coexistence technologies on "IPv4-only"
   networks and describes possible mitigations for the aforementioned
   issues.

Table of Contents

   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   2
   2.  Security Implications of Native IPv6 Support  . . . . . . . .   4
     2.1.  Filtering Native IPv6 Traffic . . . . . . . . . . . . . .   4
   3.  Security Implications of Tunneling Mechanisms . . . . . . . .   5
     3.1.  Filtering 6in4  . . . . . . . . . . . . . . . . . . . . .   6
     3.2.  Filtering 6over4  . . . . . . . . . . . . . . . . . . . .   7
     3.3.  Filtering 6rd . . . . . . . . . . . . . . . . . . . . . .   7
     3.4.  Filtering 6to4  . . . . . . . . . . . . . . . . . . . . .   8
     3.5.  Filtering ISATAP  . . . . . . . . . . . . . . . . . . . .   9
     3.6.  Filtering Teredo  . . . . . . . . . . . . . . . . . . . .   9
     3.7.  Filtering Tunnel Broker with Tunnel Setup Protocol (TSP)   11
     3.8.  Filtering AYIYA . . . . . . . . . . . . . . . . . . . . .  11
   4.  Additional Considerations when Filtering IPv6 Traffic . . . .  12
   5.  Security Considerations . . . . . . . . . . . . . . . . . . .  13
   6.  Acknowledgements  . . . . . . . . . . . . . . . . . . . . . .  13
   7.  References  . . . . . . . . . . . . . . . . . . . . . . . . .  13
     7.1.  Normative References  . . . . . . . . . . . . . . . . . .  13
     7.2.  Informative References  . . . . . . . . . . . . . . . . .  14
   Appendix A.  Summary of Filtering Rules . . . . . . . . . . . . .  18

-- 
  "One disk to rule them all, One disk to find them. One disk to bring
  them all and in the darkness grind them. In the Land of Redmond
  where the shadows lie." -- The Silicon Valley Tarot
  Henrique Holschuh



More information about the gter mailing list