Go to main content

Securing the Network in Oracle® Solaris 11.3

Exit Print View

Updated: September 2018
 
 

IPv6 for IP Filter

IPv6 packet filtering can filter based on the source/destination IPv6 address, pools containing IPv6 addresses, and IPv6 extension headers.

IPv6 is similar to IPv4 in many ways. However, header and packet size differ between the two versions of IP, which is an important consideration for IP Filter. IPv6 packets known as jumbograms contain a datagram longer than 65,535 bytes. IP Filter does not support IPv6 jumbograms.


Note - For more information on jumbograms, see IPv6 Jumbograms, RFC 2675 (http://www.ietf.org/rfc/rfc2675.txt).

IP Filter tasks associated with IPv6 do not differ substantially from IPv4. The most notable difference is the use of the –6 option with certain commands. Both the ipf command and the ipfstat command include the –6 option for use with IPv6 packet filtering. Use the –6 option with the ipf command to load and flush IPv6 packet filtering rules. To display IPv6 statistics, use the –6 option with the ipfstat command. The ipmon and ippool commands also support IPv6, although there is no associated option for IPv6 support. The ipmon command has been enhanced to accommodate the logging of IPv6 packets. The ippool command supports the pools with IPv6 addresses. You can create separate pools for IPv4 and IPv6 addresses, or a pool containing both IPv4 and IPv6 addresses.

To create re-usable IPv6 packet filtering rules, you must create a specific IPv6 file. Then, you set its pathname as the value of the config/ip6_config_file property of the IP Filter service. The default value is /etc/ipf/ipf6.conf.

For tasks associated with IP Filter, see Configuring IP Filter Firewall.