Skip to content
arrow_back
search
ISM-1429 policy ASD Information Security Manual (ISM)

Block IPv6 Tunnelling at Network Boundaries

Network security must block IPv6 tunnels at all external connections to prevent unauthorised data flow.

record_voice_over

Plain language

Blocking IPv6 tunnels at the edges of your network is about ensuring bad actors can’t sneak data in and out of your business through hidden pathways. If these tunnels aren’t blocked, unauthorised traffic could go unnoticed, potentially leading to data leaks or cyber-attacks, which could severely harm your business's integrity and operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IPv6 tunnelling is blocked by network security appliances at externally-connected network boundaries.
policy ASD Information Security Manual (ISM) ISM-1429
priority_high

Why it matters

If IPv6 tunnelling isn’t blocked at external boundaries, hidden IPv6 traffic can bypass controls, enabling data exfiltration and cyber espionage.

settings

Operational notes

Validate boundary firewalls/IDS block common IPv6 tunnels (6in4, Teredo, ISATAP) and alert on any IPv6-in-IPv4 traffic or rule drift.

Mapping detail

Mapping

Direction

Controls