SNR S2989G-24TX-UPS — настройка IPv6 и предотвращение ND спуфинга в сетях [532/553]

Превью страниц Страница 532 / 553
SNR S2989G-24TX-POE [532/553] Prevent nd spoofing configuration
S2989G-24TX Operation Manual
Chapter 11 IPv6 Configuration
11-22
second device when obtaining the false address or no address is obtained according
to option37,38.
DHCPv6 server obtains option37,38 of the packets from client by default, if no, it will
obtain option37,38 of the packet sent by relay.
DHCPv6 server only checks whether the first DHCPv6 relay adds option37,38 that
means only option37,38 of the innermost relay-forw is valid in relay packets.
11.3
Prevent ND Spoofing
11.3.1
Overview
ND is neighbor discovering protocol in IPv6 protocol, and it’s similar to ARP on
operation principle, therefore we do in the same way as preventing ARP spoofing to
prevent ND spoofing and attack.
11.3.2
Prevent ND Spoofing configuration
The steps of preventing ND spoofing configuration as below:
4. Disable ND automatic update function
5. Disable ND automatic learning function
6. Changing dynamic ND to static ND
1. Disable ND automatic update function
Command
Explanation
Global Mode and Port Mode
ipv6 nd-security updateprotect
no ipv6 nd-security updateprotect
Disable and enable ND automatic update
function.
2. Disable ND automatic learning function
Command
Explanation
Global mode and Interface Mode
ipv6 nd-security learnprotect
no ipv6 nd-security learnprotect
Disable and enable ND automatic learning
function.
3. Function on changing dynamic ND to static ND

Содержание

666

Узнайте, как настроить IPv6 и предотвратить ND спуфинг в сетевых устройствах. Следуйте простым шагам для повышения безопасности вашей сети.