Neighbor Discovery (ND)-Packet DoS Attacks
Spurious neighbor discovery (ND) packets are among the tactics employed in Denial of Service (DoS) attacks. Based on the assumption that the only valid packet hop-limit value is 255, you can configure IPv6 ACLs to drop such spurious ND packets. The following types of ND packets are checked:
- Neighbor advertisement (NA)
- Neighbor solicitation (NS)
- Router advertisement (RA)
- Router solicitation (RS)
IPv6 ACLs have the following concluding implicit rules, which impact on the hop-limit check:
- permit icmp any any nd-na: Allows ICMP neighbor discovery acknowledgements.
- permit icmp any any nd-ns: Allows ICMP neighbor discovery solicitations.
Hop-limit check enablement varies with the type of ND packet, as indicated in the following table.
Effect of ND Hop Limits on ND Rules
Hop-limit check is not applicable to any other types of rules. For example, even if hop-limit check is enabled for the ACL, it does not apply to the two following rules:
device(config-ipv6-access-list nd_acl)# permit icmp any any device(config-ipv6-access-list nd_acl)# permit ipv6 any any