Infrastructure Security - IPv6 First-Hop Security

7 important questions on Infrastructure Security - IPv6 First-Hop Security

What is the Binding Table used for IPv6 First-Hop Security?

  • The L2 binding table is a database with IPv6 neighbors.
  • Contains information like the link-layer address and the prefix binding
  • used by other IPv6 First-Hop Security features to prevent snooping and redirect attacks.

What is IPv6 Snooping?

  • A feature that captures IPv6 traffic to populate the Binding Table
  • Analyzes the IPv6 neighbor discovery messages as well as DHCPv6 messages
  • Can block Router Advertisements or DHCP replies
  • Prerequisite for all other IPv6 First-Hop security features

What is Router Advertisement (RA) Guard?

  • Used to block or reject unwanted IPv6 Router Advertisements
  • A RA Guard policy is created which is applied to an interface
  • Configured on an inbound interface
  • Two modes: Host mode and Router mode
  • No protection for IPv6 tunneled traffic
  • Only supported when TCAM is programmed
  • Not supported on EtherChannel members or Trunk ports with Merge Mode.
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

What is DHCPv6 Guard?

  • Prevents Reply and Advertisement messages from unauthorized DHCPv6 servers.
  • Classifies messages in to 3 DHCP types: Client, Server and Relay
  • switches all Clients messages and Server only when device role is Server.
  • A DHCPv6 Guard policy is created and attached to an interface

What is IPv6 Source Guard?

  • Layer 2 snooping interface feature for validating source of IPv6 traffic
  • Can block/drop traffic from unknown source.
  • Source is unknown when not in the binding table
  • Source learned through ND inspection or IPv6 Address Gleaning, therefore relies on IPv6 snooping being configured.

What is IPv6 Destination Guard?

  • Can filter IPv6 traffic based on destination address
  • Requires binding table
  • Can block NDP resolution for addresses not found in the binding table
  • By default blocks traffic coming for an unknown destination.

What is IPv6 Prefix Guard?

  • Used on ingress interfaces
  • Discovers ranges of address on a specific link
  • Denies traffic with a correct address but topologically incorrect.

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo