{"draft":"draft-ietf-opsec-ipv6-eh-filtering-10","doc_id":"RFC9288","title":"Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers at Transit Routers","authors":["F. Gont","W. Liu"],"format":["HTML","TEXT","PDF","XML"],"page_count":"33","pub_status":"INFORMATIONAL","status":"INFORMATIONAL","source":"Operational Security Capabilities for IP Network Infrastructure","abstract":"This document analyzes the security implications of IPv6 Extension\r\nHeaders and associated IPv6 options. Additionally, it discusses the\r\noperational and interoperability implications of discarding packets\r\nbased on the IPv6 Extension Headers and IPv6 options they contain.\r\nFinally, it provides advice on the filtering of such IPv6 packets at\r\ntransit routers for traffic not directed to them, for those cases\r\nwhere such filtering is deemed as necessary.","pub_date":"August 2022","keywords":["Denial of Service","Distributed Denial of Service","DoS","DDoS","ACL","filtering policy"],"obsoletes":[],"obsoleted_by":[],"updates":[],"updated_by":[],"see_also":[],"doi":"10.17487\/RFC9288","errata_url":null}