Implementation Advice for IPv6 Router Advertisement Guard (RA-Guard), February 2014
- Canonical URL:
- File formats:
- RFC 6105
- F. Gont
- v6ops (ops)
The IPv6 Router Advertisement Guard (RA-Guard) mechanism is commonly employed to mitigate attack vectors based on forged ICMPv6 Router Advertisement messages. Many existing IPv6 deployments rely on RA-Guard as the first line of defense against the aforementioned attack vectors. However, some implementations of RA-Guard have been found to be prone to circumvention by employing IPv6 Extension Headers. This document describes the evasion techniques that affect the aforementioned implementations and formally updates RFC 6105, such that the aforementioned RA-Guard evasion vectors are eliminated.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 4844.