Overview

The IPv6 ND protocol provides many functions, such as address resolution, neighbor reachability detection, duplicate address detection, router/prefix discovery and address auto-configuration, and redirection. However, it does not provide security mechanisms. Attackers can easily exploit the ND protocol to attack hosts and gateways by sending forged packets. For more information about ND, see Layer 3IP Services Configuration Guide.

ND uses the following types of ICMPv6 messages:

An attacker can attack a network by sending forged ICMPv6 messages, as shown in Figure 122:

Figure 122: ND attack diagram

All forged ND packets have these common features:

The source MAC consistency check and ND detection features can identify forged ND packets.