3.8 IPv6 Destination Guard

Information

The IPv6 Destination Guard feature in AOS-CX switches provides security by validating IPv6 traffic against a known database of allowed destinations. It ensures only authorized destination IP addresses are reachable, mitigating risks of unauthorized access or malicious activity within the network.This feature requires the binding table to be populated with the help of DHCPv6 snooping, ND snooping, or static-ip-bindings. Destination guard enables the destination address based filtering of IPv6 traffic andblocks the Neighbor Discovery (ND) protocol resolution for destination addresses that are not found inthe binding table.

With the growing adoption of IPv6, networks are exposed to a wider attack surface. IPv6 Destination Guard helps secure the network by filtering traffic based on trusted destination addresses, preventing spoofing or unauthorized communication to sensitive resources.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configuring IPV6 Destination Guard on a VLAN -

switch(config)# vlan <id>
switch(config-vlan-<id>)# ipv6 destination-guard

Impact:

Implementing IPv6 Destination Guard enhances network security by mitigating threats like IPv6 address spoofing and unauthorized data exfiltration. It contributes to a robust, reliable, and secure network environment by ensuring only legitimate IPv6 destinations are accessible.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|CA-7, 800-53|RA-5, 800-53|SC-4, 800-53|SC-7, 800-53|SI-4, CSCv7|12.2, CSCv7|13.3

Plugin: ArubaOS

Control ID: a835607e974af8e5741ced747a8ef7acdfdd3413679ad7bf24d84f1833233b65