%% You should probably cite rfc9288 instead of this I-D. @techreport{ietf-opsec-ipv6-eh-filtering-04, number = {draft-ietf-opsec-ipv6-eh-filtering-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-opsec-ipv6-eh-filtering/04/}, author = {Fernando Gont and Will (Shucheng) LIU and Ron Bonica}, title = {{Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers}}, pagetotal = 35, year = , month = , day = , abstract = {It is common operator practice to mitigate security risks by enforcing appropriate packet filtering. This document analyzes both the general security implications of IPv6 Extension Headers and the specific security implications of each Extension Header and Option type. Additionally, it discusses the operational and interoperability implications of discarding packets based on the IPv6 Extension Headers and IPv6 options they contain. Finally, it provides advice on the filtering of such IPv6 packets at transit routers for traffic *not* directed to them, for those cases in which such filtering is deemed as necessary.}, }