Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers

Document Type Expired Internet-Draft (opsec WG)
Authors Fernando Gont  , Will LIU 
Last updated 2019-10-22 (latest revision 2018-07-02)
Replaces draft-gont-opsec-ipv6-eh-filtering
Stream IETF
Intended RFC status Informational
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream WG state WG Document
Document shepherd √Čric Vyncke
Shepherd write-up Show (last changed 2018-10-29)
IESG IESG state Expired (IESG: Dead)
Consensus Boilerplate Yes
Telechat date
Responsible AD Warren Kumari
Send notices to =?utf-8?q?=C3=89ric_Vyncke?= <>
IANA IANA review state IANA OK - No Actions Needed

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


It is common operator practice to mitigate security risks by enforcing appropriate packet filtering. This document analyzes both the general security implications of IPv6 Extension Headers and the specific security implications of each Extension Header and Option type. Additionally, it discusses the operational and interoperability implications of discarding packets based on the IPv6 Extension Headers and IPv6 options they contain. Finally, it provides advice on the filtering of such IPv6 packets at transit routers for traffic *not* directed to them, for those cases in which such filtering is deemed as necessary.


Fernando Gont (
Will LIU (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)