PFBlocker List for IPV6



  • Does a Block List exist for IPV6 addresses.  Everything I find seems to only address IP4.  Can someone suggest an IPV6 blocklist, or do we only need to use snort to block?

    Thanks

    cjb



  • I have seen a couple of IPv6 lists floating around, but can't remember where. My honest opinion is IPv6 lists are useless, unless they are used to ban entire subnets. The ease with which you can jump from IP to IP on IPv6 renders a single bad host in a list useless.

    My recommendation is to use snort/suricata to keep track of bad hosts in IPv6, and based on repeated offenders in a subnet, ban the entire subnet in a list of your own. Bad IPv6 traffic is low, it's the perfect time to experiment and tweak your security systems.


Log in to reply