IPv6 Route Type 0 Filtering (Was: IPv6 Type 0 Routing Header issues)
jeroen at unfix.org
Sat Apr 28 14:47:10 CEST 2007
For the core details read:
See below of a summary on how to filter these on your platform.
I do hope that folks by now realize what this does and that they should
have applied these things like last week already... Unless you of course
want to become a victim of it: Your network will nicely suck itself up :)
"no ipv6 source-route"
Not yet, they claim to be busy with it, call your TAC and complain ;)
# Filter all packets that have RT0 headers
ip6tables -A INPUT -m rt --rt-type 0 -j DROP
ip6tables -A FORWARD -m rt --rt-type 0 -j DROP
ip6tables -A OUTPUT -m rt --rt-type 0 -j DROP
(of course before accepting anything else ;)
One has to upgrade the kernel with at least the following patch in place:
A source code patch for OpenBSD 4.0-stable can be downloaded from
A source code patch for OpenBSD 3.9-stable can be downloaded from
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 311 bytes
Desc: OpenPGP digital signature
Url : http://lists.cluenet.de/pipermail/ipv6-ops/attachments/20070428/a9b7ee03/signature.bin
More information about the ipv6-ops