Recommendations on Filtering of IPv6 Packets Containing IPv6 Extension Headers

The information below is for an old version of the document
Document Type Expired Internet-Draft (opsec WG)
Last updated 2015-09-23 (latest revision 2015-03-22)
Stream IETF
Intended RFC status (None)
Expired & archived
pdf htmlized (tools) htmlized bibtex
Additional Resources
- Mailing list discussion
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


It is common operator practice to mitigate security risks by enforcing appropriate packet filtering. This document analyzes both the general security implications of IPv6 Extension Headers and the specific security implications of each Extension Header and Option type, and provides advice on the filtering of IPv6 packets based on the IPv6 Extension Headers and the IPv6 options they contain. Additionally, it discusses the operational and interoperability implications of discarding packets based on the IPv6 Extension Headers and IPv6 options they contain.


Fernando Gont (
Will LIU (
Ron Bonica (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)