nerdexam
Cisco

300-410 · Question #72

What is a limitation of IPv6 RA Guard?

The correct answer is B. It does not offer protection in environments where IPv6 traffic is tunneled. IPv6 RA Guard's effectiveness is limited in environments where IPv6 traffic is encapsulated in tunnels, as the security feature cannot inspect the inner IPv6 Router Advertisement messages.

Infrastructure Security

Question

What is a limitation of IPv6 RA Guard?

Exhibit

300-410 question #72 exhibit

Options

  • AIt is not supported in hardware when TCAM is programmed
  • BIt does not offer protection in environments where IPv6 traffic is tunneled.
  • CIt cannot be configured on a switch port interface in the ingress direction
  • DPackets that are dropped by IPv6 RA Guard cannot be spanned

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    91% (20)
  • D
    5% (1)

Why each option

IPv6 RA Guard's effectiveness is limited in environments where IPv6 traffic is encapsulated in tunnels, as the security feature cannot inspect the inner IPv6 Router Advertisement messages.

AIt is not supported in hardware when TCAM is programmed

IPv6 RA Guard is often implemented in hardware, leveraging TCAM for efficient policy enforcement, so stating it's not supported in hardware is incorrect.

BIt does not offer protection in environments where IPv6 traffic is tunneled.Correct

IPv6 RA Guard operates by inspecting the IPv6 headers of Router Advertisement messages. If IPv6 traffic, including RA messages, is tunneled (e.g., within a GRE tunnel or IPsec), RA Guard cannot access or inspect the encapsulated IPv6 header, making it unable to detect and mitigate rogue RAs in such scenarios.

CIt cannot be configured on a switch port interface in the ingress direction

IPv6 RA Guard is specifically designed to be configured on switch port interfaces, and it commonly applies its filtering policies to traffic in the ingress direction.

DPackets that are dropped by IPv6 RA Guard cannot be spanned

While packets dropped by RA Guard will not be forwarded, the ability to span or mirror packets for analysis is a separate function and not a fundamental limitation of RA Guard's protection mechanism itself.

Concept tested: IPv6 RA Guard limitations

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_ipv6/configuration/xe-3s/ipv6-xe-3s-book/ip6-ra-guard.html

Topics

#IPv6 RA Guard#IPv6 Security#Tunneling

Community Discussion

No community discussion yet for this question.

Full 300-410 Practice