Juniper Networks, Inc.
IPV6 flow label for stateless handling of IPV4-fragments-in-IPV6

Last updated:

Abstract:

A network device may receive, from a first network, a network packet of a first network packet type that encapsulates a fragment of a second network packet of a second network packet type, where the network packet is part of a flow of a plurality of network packets of the first network packet type that encapsulates fragments of the second network packet, and where the network packet includes a flow label that indicates a source port for the second network packet. The network device may perform an anti-spoof check on the fragment of the second network packet based at least in part on the source port for the second network packet that is indicated by the flow label of the network packet. The network device may, based on the fragment passing the anti-spoof check, forward the fragment of the second network packet to a second network.

Status:
Grant
Type:

Utility

Filling date:

31 Mar 2020

Issue date:

2 Nov 2021