Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

IPv6 NDP DoS issue

More Information:

IPv6 NDP DoS issue

You can address the IPv6 Neighbor Discovery Protocol (NDP) denial-of-service (DoS) issue at the Routing Engine. Unlike IPv4 subnets, IPv6 subnets have large address spaces in which a majority of them remain unassigned. When a network scan tool or an attacker initiates traffic to nonexistent hosts through a router on a subnet that is directly connected to the router, the router attempts to perform address resolution on a large number of destinations. This condition can cause the inability to resolve new neighbors, unreachability to the existing neighbors, and can also result in a DoS attack. NDP inspection or protection addresses the NDP DoS issue by implementing the prioritization of NDP activities on the Routing Engine. At the ingress router, neighbor discovery (ND) packets are classified and handled according to a predefined priority with multiple ingress queues. On the egress path, neighbor solicitations (NS) sent for previously not seen hosts are handled with a lower priority by deferring the process of next-hop creation and sending out the packet.
Product / Application Software Introduced Release
MX5 Junos OS 16.1R1
MX10 Junos OS 16.1R1
MX40 Junos OS 16.1R1
MX80 Junos OS 16.1R1
MX104 Junos OS 16.1R1
MX204 Junos OS 17.4R1
MX240 Junos OS 16.1R4
MX240 Junos OS 16.1R1
MX301 Junos OS 25.4R1
MX304 Junos OS 22.2R3
MX480 Junos OS 16.1R4
MX480 Junos OS 16.1R1
MX960 Junos OS 16.1R4
MX960 Junos OS 16.1R1
MX2010 Junos OS 16.1R4
MX2010 Junos OS 16.1R1
MX2020 Junos OS 16.1R4
MX2020 Junos OS 16.1R1
MX10003 Junos OS 17.3R1
MX10004 Junos OS 22.3R1
MX10008 Junos OS 18.2R1
MX10016 Junos OS 19.2R1