300-410 · Question #72
What is a limitation of IPv6 RA Guard?
The correct answer is B. It does not offer protection in environments where IPv6 traffic is tunneled. IPv6 RA Guard's effectiveness is limited in environments where IPv6 traffic is encapsulated in tunnels, as the security feature cannot inspect the inner IPv6 Router Advertisement messages.
Question
Exhibit
Options
- AIt is not supported in hardware when TCAM is programmed
- BIt does not offer protection in environments where IPv6 traffic is tunneled.
- CIt cannot be configured on a switch port interface in the ingress direction
- DPackets that are dropped by IPv6 RA Guard cannot be spanned
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Why each option
IPv6 RA Guard's effectiveness is limited in environments where IPv6 traffic is encapsulated in tunnels, as the security feature cannot inspect the inner IPv6 Router Advertisement messages.
IPv6 RA Guard is often implemented in hardware, leveraging TCAM for efficient policy enforcement, so stating it's not supported in hardware is incorrect.
IPv6 RA Guard operates by inspecting the IPv6 headers of Router Advertisement messages. If IPv6 traffic, including RA messages, is tunneled (e.g., within a GRE tunnel or IPsec), RA Guard cannot access or inspect the encapsulated IPv6 header, making it unable to detect and mitigate rogue RAs in such scenarios.
IPv6 RA Guard is specifically designed to be configured on switch port interfaces, and it commonly applies its filtering policies to traffic in the ingress direction.
While packets dropped by RA Guard will not be forwarded, the ability to span or mirror packets for analysis is a separate function and not a fundamental limitation of RA Guard's protection mechanism itself.
Concept tested: IPv6 RA Guard limitations
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_ipv6/configuration/xe-3s/ipv6-xe-3s-book/ip6-ra-guard.html
Topics
Community Discussion
No community discussion yet for this question.
