Unfortunately, that answer won't survive a security audit. I need to prove that the listening services bound to ipv6 interfaces are properly firewalled. I do not know much about ipv6 but these services appear wide open. Am I misundestanding?
# ip6tables -nvL
Chain INPUT (policy ACCEPT 0...