%% You should probably cite draft-ietf-v6ops-balanced-ipv6-security-01 instead of this revision. @techreport{ietf-v6ops-balanced-ipv6-security-00, number = {draft-ietf-v6ops-balanced-ipv6-security-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-v6ops-balanced-ipv6-security/00/}, author = {Martin Gysi and Guillaume Leclanche and Éric Vyncke and Ragnar Anfinsen}, title = {{Balanced Security for IPv6 Residential CPE}}, pagetotal = 7, year = 2013, month = oct, day = 21, abstract = {This document describes how an IPv6 residential Customer Premise Equipment (CPE) can have a balanced security policy that allows for a mostly end-to-end connectivity while keeping the major threats outside of the home. It is based on an actual IPv6 deployment by Swisscom and allows all packets inbound/outbound EXCEPT for some layer-4 ports where attacks and vulnerabilities (such as weak passwords) are well-known. The blocked inbound ports is expected to be updated as threats come and go.}, }