![Brocade Communications Systems ICX 7250 series Скачать руководство пользователя страница 153](http://html1.mh-extra.com/html/brocade-communications-systems/icx-7250-series/icx-7250-series_configuration-manual_2817203153.webp)
NOTE
The actual reachable time will be from 0.5 to 1.5 times the configured or default
value.
IPv6 neighbor discovery inspection
IPv6 ND inspection is an internal network security system that detects and prevents IPv6 address spoofing at the switch level.
IP communication within a Layer 2 infrastructure is established by mapping an IP address to a MAC address. An invalid host can
intercept packet flow between legitimate hosts by sending a neighbor solicitation or neighbor advertisement with a forged IP-to-MAC
address binding. The victim host includes an illegitimate entry in the neighbor cache, which is looked up to validate the IP-to-MAC
address binding. After a successful attack, all the traffic will be redirected through the invalid host and is vulnerable to man-in-the-middle
attacks. The ND inspection validates all the IPv6 packets carrying neighbor discovery messages by checking the IP-to-MAC address
binding of the packets. If there is a discrepancy in the IP-to-MAC address binding, the neighbor discovery message is considered to be
from an invalid host and the packets are discarded.
The following figure illustrates the method by which Host 3 performs ND cache poisoning by sending a neighbor solicitation message to
Host 1 with the source IP of Host 2, and similarly to Host 2 with the source IP of Host 1, with its own MAC address. By doing this, Host
3 can intercept the packet flow from Host 1 to Host 2.
FIGURE 12
Neighbor discovery cache poisoning
IPv6 neighbor discovery inspection
Brocade FastIron Layer 3 Routing Configuration Guide
53-1003903-04
153
Содержание ICX 7250 series
Страница 2: ...Brocade FastIron Layer 3 Routing Configuration Guide 2 53 1003903 04...
Страница 16: ...Brocade FastIron Layer 3 Routing Configuration Guide 16 53 1003903 04...
Страница 20: ...Brocade FastIron Layer 3 Routing Configuration Guide 20 53 1003903 04...
Страница 36: ...Brocade FastIron Layer 3 Routing Configuration Guide 36 53 1003903 04...
Страница 124: ...Brocade FastIron Layer 3 Routing Configuration Guide 124 53 1003903 04...
Страница 174: ...Brocade FastIron Layer 3 Routing Configuration Guide 174 53 1003903 04...
Страница 188: ...Brocade FastIron Layer 3 Routing Configuration Guide 188 53 1003903 04...
Страница 202: ...Brocade FastIron Layer 3 Routing Configuration Guide 202 53 1003903 04...
Страница 470: ...Brocade FastIron Layer 3 Routing Configuration Guide 470 53 1003903 04...