<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-v6ops-balanced-ipv6-security" target="https://datatracker.ietf.org/doc/html/draft-ietf-v6ops-balanced-ipv6-security-00">
   <front>
      <title>Balanced Security for IPv6 Residential CPE</title>
      <author initials="M." surname="Gysi" fullname="Martin Gysi">
         </author>
      <author initials="G." surname="Leclanche" fullname="Guillaume Leclanche">
         </author>
      <author initials="E." surname="Vyncke" fullname="Éric Vyncke">
         </author>
      <author initials="R." surname="Anfinsen" fullname="Ragnar Anfinsen">
         </author>
      <date month="October" day="21" year="2013" />
      <abstract>
	 <t>   This document describes how an IPv6 residential Customer Premise
   Equipment (CPE) can have a balanced security policy that allows for a
   mostly end-to-end connectivity while keeping the major threats
   outside of the home.  It is based on an actual IPv6 deployment by
   Swisscom and allows all packets inbound/outbound EXCEPT for some
   layer-4 ports where attacks and vulnerabilities (such as weak
   passwords) are well-known.  The blocked inbound ports is expected to
   be updated as threats come and go.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-v6ops-balanced-ipv6-security-00" />
   
</reference>
