Block IPv6 Tunnelling at Externally Connected Network Boundaries
Configure your network security appliances to block IPv6 tunnelling traffic at every point where your network connects to the outside world.
Plain language
Computers use addressing systems called Internet Protocol (IP) to talk to each other, and there are two versions in use: the older IPv4 and the newer IPv6. "IPv6 tunnelling" is a trick that wraps newer IPv6 traffic inside older IPv4 traffic so it can sneak through equipment that was only set up to watch IPv4. This control says your firewalls and other security equipment that sit at the edge of your network (where it joins the internet or any outside network) must be set to block that kind of hidden tunnelling traffic. It matters because attackers and malware can use these tunnels to slip past your defences and quietly move data in or out without being seen.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for networkingOfficial control statement
IPv6 tunnelling is blocked by network security appliances at externally connected network boundaries.
Why it matters
If IPv6 tunnelling is not blocked at the network edge, attackers or malware can hide traffic inside permitted connections to bypass firewalls and silently steal data or maintain remote access.
Operational notes
Re-confirm the IPv6 tunnelling block whenever firewalls, internet providers or firmware change, and review the rules during scheduled firewall audits so they are not lost over time.
Implementation tips
- The IT or network administrator should identify every place where your network connects to an external network (for example, the internet link, partner connections or a remote office link) and confirm a network security appliance such as a firewall sits at each of those boundaries.
- The network administrator should configure each boundary firewall with explicit rules that block known IPv6 tunnelling protocols, including 6to4, Teredo, ISATAP and 6in4, rather than relying on default settings that may quietly allow them.
- Where your organisation does not yet use IPv6 internally, the IT administrator should disable IPv6 tunnelling on workstations and servers and block the related protocol numbers (such as protocol 41) and UDP ports used by Teredo at the network edge.
- The network administrator should test the blocking by attempting to set up a tunnel from inside the network to an outside address and confirming the security appliance drops or rejects the attempt, then save the test result.
- The IT manager should add a check for IPv6 tunnelling rules to the regular firewall review schedule so the rules are reconfirmed after any change to network equipment, internet provider or firmware update.
Audit / evidence tips
- Askthe current firewall or network security appliance rule set covering each external network boundaryLook atexplicit rules that deny IPv6 tunnelling protocols (6to4, Teredo, ISATAP, 6in4, protocol 41)Goodshows named rules that block these at every external boundary, not just a vague claim that the firewall handles it
- Askthe network administrator to show which connection points count as externally connected boundaries and how each is protectedLook ata simple network diagramGoodaccounts for every internet and external link, including remote sites and backup links, with a security appliance on each
- Askevidence that the blocking actually works, such as a test record or a captured log showing a tunnelling attempt being droppedGoodis a dated test result or appliance log, not just an assertion that the rules exist
- Askhow IPv6 tunnelling rules are kept in place after changesLook atthe firewall change or review logGoodshows the rules are re-checked after firmware updates, provider changes or appliance replacements, with dates and who did it
- Askwhether IPv6 is used internally and how that affects the tunnelling controlsLook ata clear decision:Goodeither confirms IPv6 tunnelling is blocked because it is not needed, or explains how legitimate IPv6 is handled natively while still blocking unauthorised tunnels
Cross-framework mappings
How ISM-1429 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 8.12 | ISM-1429 requires blocking IPv6 tunnelling at externally-connected network boundaries to prevent unauthorised data flows that can bypass ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Networking
See all Guidelines for networking controls, or browse the full ASD ISM library.