Neighbor Discovery (ND)-Packet DoS Attacks

Checking for neighbor discovery (ND) packets with a hop limit less than 255 helps protect against Denial of Service (DoS) attacks.

Spurious neighbor discovery (ND) packets are among the tactics employed in Denial of Service (DoS) attacks. Based on the assumption that the only valid packet hop-limit value is 255, you can configure IPv6 ACLs to drop such spurious ND packets. The following types of ND packets are checked:

  • Neighbor advertisement (NA)
  • Neighbor solicitation (NS)
  • Router advertisement (RA)
  • Router solicitation (RS)
Note: ND-packet hop-limit check is enabled by default.

IPv6 ACLs have the following concluding implicit rules, which impact on the hop-limit check:

  • permit icmp any any nd-na: Allows ICMP neighbor discovery acknowledgements.
  • permit icmp any any nd-ns: Allows ICMP neighbor discovery solicitations.

Hop-limit check enablement varies with the type of ND packet, as indicated in the following table.

Effect of ND Hop Limits on ND Rules

Packet Type
Implicit or Configured Rules
Hop-Limit Check
ND acknowledgement
implicit permit
Yes
ND acknowledgement
permit icmp … nd-na
Yes
ND solicitation
implicit permit
Yes
ND solicitation
permit icmp … nd-ns
Yes
router advertisement
permit icmp … router-advertisement
Yes
router advertisement
If not specifically permitted,
denied by the implicit deny ipv6 any any.
No
router solicitation
permit icmp … router-solicitation
Yes
router solicitation
If not specifically permitted,
denied by the implicit deny ipv6 any any.
No

Hop-limit check is not applicable to any other types of rules. For example, even if hop-limit check is enabled for the ACL, it does not apply to the two following rules:

device(config-ipv6-access-list nd_acl)# permit icmp any any
device(config-ipv6-access-list nd_acl)# permit ipv6 any any