Introduction, Overview, and Motivations
Introduction and Motivations
IPv6 Overview
Overview of Traditional Security Approaches and Mechanisms
Basic IPv6 Protocol Mechanisms
IPv6 Addressing Mechanisms
Address Types
Addresses for Hosts and Routers
IPv6 Addressing (Details)
IANA Considerations
Creating Modified EUI-64 Format Interface Identifiers
64-Bit Global Identifier (EUI-64) Registration Authority
More Advanced IPv6 Protocol Mechanisms
IPv6 and Related Protocols (Details)
IPv6 Header Format
IPv6 Extension Headers
Packet Size Issue
Flow Labels
Traffic Classes
Upper-Layer Protocol Issues
Semantics and Usage of the Flow Label Field
Formatting Guidelines for Options
IPv6 Infrastructure
Routing and Route Management
Configuration Methods
Dynamic Host Configuration Protocol for IPv6
More on Transition Approaches and Mechanisms
Security Mechanisms and Approaches
Security 101
Review of Firewall-Based Perimeter Security
IPv6 Areas of Security Concerns: Addresses
Documented Issues for IPv6 Security
Basic IPv6 Security Considerations
IPv6 Flow Labels Issues
ICMPv6 Issues
Neighbor Discovery Issues
Routing Headers
DNS Issues
Minimum Security Plan
IPsec and Its Use in IPv6 Environments
Overview
IPsec Modes
IP Authentication Header (AH)
IP Encapsulating Security Protocol (ESP)
Supportive Infrastructure: IPsec Architecture
Related Observations
Firewall Use in IPv6 Environments
Role of Firewalls for IPv6 Perimeters
Packet Filtering
Extension Headers and Fragmentation
Concurrent Processing
Firewall Functionality
Related Tools
Security Considerations for Migrations/Mixed IPv4-IPv6 Networks
Transition Basics
Security Issues Associated with Transition
Threats and the Use of IPsec
NATs, Packet Filtering, and Teredo
Use of Host-Based Firewalls
Use of Distributed Firewalls
Biography
Daniel Minoli, director of terrestrial systems engineering for SES Americom, has done extensive work with IPv6, including four books on the subject.
Jake Kouns (CISSP, CISA, CISM), director of information security and network services for Markel Corporation, is also co-founder and president of the Open Security Foundation.






