<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.davies-v6ops-icmpv6-filtering-bcp" target="https://datatracker.ietf.org/doc/html/draft-davies-v6ops-icmpv6-filtering-bcp-00">
   <front>
      <title>Best Current Practice for Filtering ICMPv6 Messages in Firewalls</title>
      <author initials="E. B." surname="Davies" fullname="Elwyn B. Davies">
         <organization>Consultant</organization>
      </author>
      <author initials="J." surname="Mohácsi" fullname="János Mohácsi">
         <organization>NIIF/HUNGARNET</organization>
      </author>
      <date month="July" day="12" year="2005" />
      <abstract>
	 <t>   In networks supporting IPv6 the Internet Control Message Protocol
   version 6 (ICMPv6) plays a fundamental role with a large number of
   functions, and a correspondingly large number of message types and
   options.  A number of security risks are associated with uncontrolled
   forwarding of ICMPv6 messages, and it is desirable to configure site
   firewalls to intercept inappropriate usages of ICMPv6 which might
   allow an attacker outside a site to probe or compromise the site
   network.  On the other hand, compared with IPv4 and the corresponding
   protocol ICMP, ICMPv6 is essential to the functioning of IPv6 rather
   than a useful auxiliary.  Hence too aggressive filtering of ICMPv6
   messages can be detrimental to the establishment of IPv6
   communications.  This means that effective filtering of ICMPv6
   requires a more complex configuration than was needed for ICMP.  This
   document provides some recommendations for ICMPv6 firewall filter
   configuration that will allow propagation of ICMPv6 messages that are
   needed to maintain the functioning of the network but drop messages
   which are potential security risks.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-davies-v6ops-icmpv6-filtering-bcp-00" />
   
</reference>
