Just got assigned to lead an #IPv6 security assessment. Been using it since 6bone, but there are little features/functionality/helper protocols that I'm not familiar with.

Anyone wanna give me a brain dump of things to look into? Stuff that differs from IPv4.

Boost please :)
Follow

@farhan

Search for IPv6 here dev-sec.io/baselines/linux/ this covers mostly ND and ICMPv6 related controls in Linux but easy to generalize

Is rp_filter enabled (kernel)

Are IPv6 bogons blocked on input and output (firewall)

team-cymru.com/community-servi

Access controls - IPv6 needs proper firewalls configured as you can no longer rely on half-baked solutions like NAT for access controls.

Privacy extensions on clients

Specific ICMPv6 types to be allowed

If they use BGP, do they follow MANRS

Β· Β· 0 Β· 1 Β· 2
Sign in to participate in the conversation
Mastodon πŸ” privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!