300-360 · Question #154
You must configure IPV6 to drop unwanted or rogue RA packets that come from wireless clients. Which feature do you enable?
The correct answer is D. RA guard. RA Guard (Router Advertisement Guard) is a Layer 2 security feature that inspects ICMPv6 Router Advertisement messages and drops any RA packets sourced from unauthorized devices - such as rogue wireless clients attempting to spoof a default gateway. DHCPv6 Server Guard blocks…
Question
You must configure IPV6 to drop unwanted or rogue RA packets that come from wireless clients. Which feature do you enable?
Options
- ADHCPv6 Server Guard
- BIPv6 Source Guard
- CRA throttling
- DRA guard
How the community answered
(53 responses)- A8% (4)
- B2% (1)
- C4% (2)
- D87% (46)
Explanation
RA Guard (Router Advertisement Guard) is a Layer 2 security feature that inspects ICMPv6 Router Advertisement messages and drops any RA packets sourced from unauthorized devices - such as rogue wireless clients attempting to spoof a default gateway. DHCPv6 Server Guard blocks unauthorized DHCPv6 servers but does not address RA packets. IPv6 Source Guard validates IPv6 source addresses against a binding table. RA Throttling limits the rate of RA forwarding but does not block rogue RAs. Only RA Guard specifically enforces which ports are permitted to send RA messages.
Topics
Community Discussion
No community discussion yet for this question.