NET-IPV6-008 - IPV6 Bogons are not blocked - 'deny ipv6 any 3FFE::/16 log'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The IAO/NSO will ensure IPv6 6bone address space is blocked on the ingress and egress filter, (3FFE--/16).

The decommissioned 6bone allocation (3FFE--/16), RFC 3701 must be blocked. It is no longer a trusted source.

NOTE: Change 'IPV6_INGRESS_ACL' to the access control list for IPv6 inbound connection filtering.

Solution

The administrator will configure the router ACLs to restrict IP addresses that contain any 6bone addresses.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, Rule-ID|SV-20165r1_rule, STIG-ID|NET-IPV6-008, Vuln-ID|V-18610

Plugin: Cisco

Control ID: b0e1e2efc2e7dc8ca9d9656f6f8639dff2a6b215ba6d5dd943594cecf7ca43ef