@techreport{guichard-spring-srv6-simplified-firewall-02, number = {draft-guichard-spring-srv6-simplified-firewall-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-guichard-spring-srv6-simplified-firewall/02/}, author = {Jim Guichard and Clarence Filsfils and Daniel Bernier and Zhenbin Li and Francois Clad and Pablo Camarillo and Ahmed Abdelsalam}, title = {{Simplifying Firewall Rules with Network Programming and SRH Metadata}}, pagetotal = 7, year = 2020, month = apr, day = 8, abstract = {A clear application of the SRv6 Network Programming model consists in steering, in a stateless manner, packets through a Service Function Chain (SFC). Each Service Function (SF) is identified by a segment. Each SF can enrich its operation thanks to metadata present in the SRH. This document describes a practical use-case where the SF is a firewall and the metadata helps to drastically decrease the number of rules that need to be maintained by the operation team.}, }