<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.v6ops-vyncke-balanced-ipv6-security" target="https://datatracker.ietf.org/doc/html/draft-v6ops-vyncke-balanced-ipv6-security-01">
   <front>
      <title>Balanced Security for IPv6 CPE</title>
      <author initials="M." surname="Gysi" fullname="Martin Gysi">
         <organization>Swisscom</organization>
      </author>
      <author initials="G." surname="Leclanche" fullname="Guillaume Leclanche">
         <organization>Swisscom</organization>
      </author>
      <author initials="E." surname="Vyncke" fullname="Éric Vyncke">
         <organization>Cisco Systems</organization>
      </author>
      <author initials="R." surname="Anfinsen" fullname="Ragnar Anfinsen">
         <organization>Altibox</organization>
      </author>
      <date month="July" day="15" year="2013" />
      <abstract>
	 <t>   This document describes how an IPv6 residential Customer Premise
   Equipment (CPE) can have a balanced security policy that allows for a
   mostly end-to-end connectivity while keeping the major threats
   outside of the home.  It is based on an actual IPv6 deployment by
   Swisscom and proposes to allow all packets inbound/outbound EXCEPT
   for some layer-4 ports where attacks and vulnerabilities (such as
   weak passwords) are well-known.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-v6ops-vyncke-balanced-ipv6-security-01" />
   
</reference>
