IPv6 ND Proxy

IPv6 ND Proxy enables the hosts in different broadcast domains with identical subnet masks to communicate with each other.

IPv6 ND Proxy

In the example, host H1 wants to send packets to host H2. However, host H1 does not know the link-layer address of destination host H2 or is in a different broadcast domain which is directly connected to the proxy router. When ND proxy is enabled on the router globally, the hosts on different broadcast domains with identical subnet masks respond with the link-layer address. The source H1 multicasts an ICMPv6 neighbor solicitation message using its MAC address and Ipv6 address to find the link-layer address. The solicited-node multicast MAC address corresponding to the destination host H2 will be the destination MAC address. The target address is the destination IPv6 address. The neighbor solicitation message gets forwarded to the router. The router will update its neighbor cache table with this neighbor solicitation message. The neighbor solicitation packet contains the following information:

  • Source MAC address: MAC address of host H1
  • Destination MAC address: Solicited-node multicast MAC address of destination host H2
  • IPv6 source address: Global unique IPv6 address of host H1
  • IPv6 destination address: Solicited-node multicast address of destination host H2
  • Target address: Global unique IPv6 address of host H2

The outgoing proxy-enabled interface 2 modifies the received neighbor solicitation packet before sending it to the destination H2. The proxy interface generates a proxy neighbor solicitation packet. The source link-layer address of the neighbor solicitation packet will be changed to link-layer address of the ND proxy-enabled interface 2 in the proxy neighbor solicitation packet. The proxy neighbor solicitation packet contains the following information:

  • Source MAC address: MAC address of host H1 will be changed to MAC address of proxy interface 2
  • Destination MAC address: Solicited-node multicast MAC address of destination host H2
  • IPv6 source address: Global unique IPv6 address of egress interface 2
  • IPv6 destination address: Solicited-node multicast address of destination host H2
  • Target address: Global unique IPv6 address of host H2

The proxy neighbor solicitation message from proxy interface 2 is forwarded to the destination host H2. Host H2 gives replies to this proxy neighbor solicitation message because the solicited-node multicast address is derived from its own IPv6 address. The destination host H2 replies by sending a neighbor advertisement message that carries its link-layer information. The neighbor advertisement message reaches the router and updates the neighbor table. The neighbor advertisement packet contains the following information:

  • Source MAC address: MAC address of host H2
  • Destination MAC address: MAC address of proxy interface 2
  • IPv6 source address: Source global IPv6 address of host H2
  • IPv6 destination address: The link-local address of proxy interface 2

The neighbor advertisement packet reaches the router. This router initiates a proxy neighbor advertisement packet for the second neighbor solicitation request from the source host H2 because the neighbor cache table has the details of target host H1. The proxy neighbor advertisement packet contains the following information:

  • Source MAC address: MAC address of proxy interface 1 instead of the H2 MAC address
  • Destination MAC address: MAC address of host H1
  • IPv6 source address: Source global IPv6 address of egress interface 1
  • IPv6 destination address: Destination address of host H1

After the host H1 receives the proxy neighbor advertisement packet, both the hosts in different networks communicate with each other.