RFC 6324: Routing Loop Attack Using IPv6 Automatic Tunnels: Problem Statement and Proposed Mitigations
In plain English — editorial summary, not part of the RFC
This document is concerned with security vulnerabilities in IPv6-in- IPv4 automatic tunnels. These vulnerabilities allow an attacker to take advantage of inconsistencies between the IPv4 routing state and the IPv6 routing state. The attack forms a routing loop that can be abused as a vehicle for traffic amplification to facilitate denial- of-service (DoS) attacks. The first aim of this document is to inform on this attack and its root causes. The second aim is to present some possible mitigation measures. It should be noted that at the time of this writing there are no known reports of malicious attacks exploiting these vulnerabilities. Nonetheless, these vulnerabilities can be activated by accidental misconfiguration. This document is not an Internet Standards Track specification; it is published for informational purposes.
Document record
- Document ID
- RFC6324
- Published
- August 2011
- Authors
- G. Nakibly; F. Templin
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 19
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6179The Internet Routing Overlay Network (IRON)Current
March 2011
- RFC 6139Routing and Addressing in Networks with Global Enterprise Recursion (RANGER) ScenariosCurrent
February 2011
- RFC 5579Transmission of IPv4 Packets over Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) InterfacesCurrent
February 2010
- RFC 7084Basic Requirements for IPv6 Customer Edge RoutersUpdated
November 2013
- RFC 6040Tunnelling of Explicit Congestion NotificationUpdated
November 2010
- RFC 5969IPv6 Rapid Deployment on IPv4 Infrastructures (6rd) -- Protocol SpecificationCurrent
August 2010
- RFC 6935IPv6 and UDP Checksums for Tunneled PacketsCurrent
April 2013
- RFC 5512The BGP Encapsulation Subsequent Address Family Identifier (SAFI) and the BGP Tunnel Encapsulation AttributeObsoleted
April 2009
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?