PF support for IPv6 Extension Headers

Fernando Gont-2

What's the level of support in PF wrt IPv6 Extension Headers?

pf.conf(5) talks about an implicit block rule for packets employing the
routing header, but I've not been able to find anything about e.g.,

* Filtering packets on a per-EH-type-occurrence (e.g. "block packets
that contain a Destination Options Header")

* Filtering packets base on the EH size

* Filtering packets based on the number of EHs they contain (e.g., drop
the packet if it employs more than 5 EHs)




