RFC 6583: Operational Neighbor Discovery Problems
In plain English — editorial summary, not part of the RFC
In IPv4, subnets are generally small, made just large enough to cover the actual number of machines on the subnet. In contrast, the default IPv6 subnet size is a /64, a number so large it covers trillions of addresses, the overwhelming number of which will be unassigned. Consequently, simplistic implementations of Neighbor Discovery (ND) can be vulnerable to deliberate or accidental denial of service (DoS), whereby they attempt to perform address resolution for large numbers of unassigned addresses. Such denial-of-service attacks can be launched intentionally (by an attacker) or result from legitimate operational tools or accident conditions. As a result of these vulnerabilities, new devices may not be able to "join" a network, it may be impossible to establish new IPv6 flows, and existing IPv6 transported flows may be interrupted. This document describes the potential for DoS in detail and suggests possible implementation improvements as well as operational mitigation techniques that can, in some cases, be used to protect against or at least alleviate the impact of such attacks. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6583
- Published
- March 2012
- Authors
- I. Gashinsky; J. Jaeggli; W. Kumari
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 12
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6589Considerations for Transitioning Content to IPv6Current
April 2012
- RFC 6576IP Performance Metrics (IPPM) Standard Advancement TestingCurrent
March 2012
- RFC 6555Happy Eyeballs: Success with Dual-Stack HostsObsoleted
April 2012
- RFC 6615Definitions of Managed Objects for IP Flow Information ExportCurrent
June 2012
- RFC 6536Network Configuration Protocol (NETCONF) Access Control ModelObsoleted
March 2012
- RFC 6632An Overview of the IETF Network Management StandardsCurrent
June 2012
- RFC 6534Loss Episode Metrics for IP Performance Metrics (IPPM)Current
May 2012
- RFC 6526IP Flow Information Export (IPFIX) Per Stream Control Transmission Protocol (SCTP) StreamCurrent
March 2012
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?