RFC 4891:Using IPsec to Secure IPv6-in-IPv4 Tunnel...
RFC-Ref

Spoofing


Click on the red underlined text to get to the source

... [RFC4213] is mostly concerned about address spoofing threats: 1. The IPv4 ...
... SA. Thus, the outer address spoofing is irrelevant as long as the decryption succeeds and the inner IPv6 packet ...


... ingress filtering must be performed to mitigate the IPv6 address spoofing threat. A specific case of router-to-router ...
... IPv6 spoofing must be prevented, and setting up ingress filtering may ...
... IPv6 source address spoofing completely. As noted in the Introduction, automatic host-to-host ...


... tunnel interface. Source address spoofing can be limited by enabling ingress filtering on the tunnel ...


... Internet, it is possible to "inject" packets into the tunnel by spoofing the source address (data plane security ...



Google
Web
RFC-Ref