Skip to content
arrow_back
search
ISM-1428 policy ASD Information Security Manual (ISM)

Disable IPv6 Tunnelling Unless Necessary

IPv6 tunnelling on network devices should be disabled unless absolutely needed.

record_voice_over

Plain language

This control is about turning off a technology feature called 'IPv6 tunnelling' in your network devices unless you really need it. Imagine it as a back door to your network; if left open unnecessarily, it could let bad actors sneak in unnoticed. It's important to keep your digital doors locked to protect sensitive information and keep your business operations running smoothly.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
policy ASD Information Security Manual (ISM) ISM-1428
priority_high

Why it matters

If IPv6 tunnelling is left enabled, attackers can bypass IPv4 security controls and monitoring, enabling unauthorised access or data exfiltration.

settings

Operational notes

Confirm IPv6 tunnelling (e.g. 6to4, Teredo, ISATAP) is disabled on routers, firewalls and hosts; only enable via approved change and re-check configs.

Mapping detail

Mapping

Direction

Controls