Securing the Data Plane in IPv6 Flashcards
Can these numbers 2345, 3456 be valid first four characters of a globally routable IPv6 address?
Yes
What are the valid first four characters of a link-local address?
FE80
What is the default method for determining the interface ID for a link-local address on ethernet?
EUI-64
How many groups of four hexadecimal characters does an IPv6 address contain?
8
Which routing protocols have both an IPv4 and IPv6 version?
RIP, EIGRP, OSPF
Which best practices apply to networks that run both IPv4 and IPv6?
Physical security, Routing protocol authentication, Authorization of administrators, Written security policy
Which protocols, if abused, could impair an IPv6 network, but not IPv4?
NDP, Solicited node multicast addresses
If a rogue IPv6 router is allowed on the network, which information could be incorrectly delivered to the clients on that network?
IPv6 default gateway, IPv6 DNS server, IPv6 network address
Why is tunneling any protocol (including IPv6) through another protocol a security risk?
The innermost contents of the original packets may be hidden from normal security filters, The tunnels, if they extend beyond the network perimeter, may allow undesired traffic through the tunnel
What is one method to protect against a rogue IPv6 router?
RA guard