Internet Engineering Task Force (IETF) N. Hilliard
Request for Comments: 6666 INEX
Category: Informational D. Freedman
ISSN: 2070-1721 Claranet
August 2012
A Discard Prefix for IPv6
Hilliard & Freedman Informational [Page 1]
RFC 6666 IPv6 Discard Prefix August 2012
Copyright Notice
1. Introduction
Remote Triggered Black Hole (RTBH) filtering describes a class of methods of blocking IP traffic either from a specific source ([RFC5635]) or to a specific destination ([RFC3882]) on a network. RTBH routing describes a class of methods of re-routing IP traffic destined to the attacked/targeted host to a special path (tunnel) where a sniffer could capture the traffic for analysis. Both of these methods operate by setting the next-hop address of an IP packet with a specified source or destination address to be a unicast prefix that is connected locally or remotely to a router's discard, null, or tunnel interface. Typically, reachability information for this prefix is propagated throughout an autonomous system using a dynamic routing protocol such as BGP ([RFC3882]). By deploying RTBH systems across a network, traffic to or from specific destinations may be selectively black-holed or re-routed to a sinkhole device in a manner that is efficient, scalable, and straightforward to implement. On some networks, operators configure RTBH installations using [RFC1918] address space or the address blocks reserved for documentation in [RFC5737]. This approach is inadequate because RTBH configurations are not documentation, but rather operationally important features of many public-facing production networks. Furthermore, [RFC3849] specifies that the IPv6 documentation prefix should be filtered in both local and public contexts. On this basis, it is suggested that both private network address blocks and the documentation prefixes described in [RFC5737] are inappropriate for RTBH configurations and that a dedicated IPv6 prefix should be assigned instead.
Hilliard & Freedman Informational [Page 2]
RFC 6666 IPv6 Discard Prefix August 2012
This document updates the "IPv6 Special Purpose Address Registry" [IANA-IPV6REG].
1.1. Notational Conventions
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
2. A Discard Prefix for IPv6
For the purposes of implementing an IPv6 RTBH configuration, a unicast address block is required. There are currently no IPv6 unicast address blocks that are specifically nominated for the purposes of implementing such RTBH systems.
Hilliard & Freedman Informational [Page 3]
RFC 6666 IPv6 Discard Prefix August 2012 3. Operational ImplicationsThis assignment MAY be carried in a dynamic routing protocol within an autonomous system. The assignment SHOULD NOT be announced to or accepted from third-party autonomous systems, and IPv6 traffic with a destination address within this prefix SHOULD NOT be forwarded to or accepted from third-party autonomous systems. If the prefix or a subnet of the prefix is inadvertently announced to or accepted from a third-party autonomous system, this may cause excessive volumes of traffic to pass unintentionally between the two networks, which would aggravate the effect of a denial-of-service attack.
4. IANA Considerations
Per this document, IANA has recorded the allocation of the IPv6 address prefix 0100::/64 as a Discard-Only Prefix in the "Internet Protocol Version 6 Address Space" and added the prefix to the "IANA IPv6 Special Purpose Address Registry" [IANA-IPV6REG]. No end party has been assigned to this prefix. The prefix has been allocated from ::/3.
5. Security Considerations
As the prefix specified in this document ought not normally be transmitted or accepted over inter-domain BGP sessions for the reasons described in Section 3, it is usually appropriate to include this prefix in inter-domain BGP prefix filters [RFC3704] or otherwise ensure the prefix is neither transmitted to nor accepted from a third-party autonomous system.
Hilliard & Freedman Informational [Page 4]
RFC 6666 IPv6 Discard Prefix August 2012 6. References 6.1. Normative References[IANA-IPV6REG]
6.2. Informative References
[RFC1918] Rekhter, Y., Moskowitz, B., Karrenberg, D., de Groot, G.,
Hilliard & Freedman Informational [Page 5]
RFC 6666 IPv6 Discard Prefix August 2012
Authors' Addresses