RFC 9898: Neighbor Discovery Considerations in IPv6 Deployments
In plain English — editorial summary, not part of the RFC
The Neighbor Discovery (ND) protocol is a critical component of the IPv6 architecture. The protocol uses multicast in many messages. It also assumes a security model where all nodes on a link are trusted. Such a design might be inefficient in some scenarios (e.g., use of multicast in wireless networks) or when nodes are not trustworthy (e.g., public access networks). These security and operational issues and the associated mitigation solutions are documented in more than twenty RFCs. There is a need to track these issues and solutions in a single document. To that aim, this document summarizes the published ND issues and then describes how all these issues originate from three causes. Addressing the issues is made simpler by addressing the causes. This document also analyzes the mitigation solutions and demonstrates that isolating hosts into different subnets and links can help to address the three causes. Guidance is provided for selecting a suitable isolation method to prevent potential ND issues.
Document record
- Document ID
- RFC9898
- Published
- November 2025
- Authors
- X. Xiao; E. Vasilenko; E. Metz; G. Mishra; N. Buraglio
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 26
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9663Using DHCPv6 Prefix Delegation (DHCPv6-PD) to Allocate Unique IPv6 Prefixes per Client in Large Broadcast NetworksCurrent
October 2024
- RFC 8161Benchmarking the Neighbor Discovery ProtocolCurrent
May 2017
- RFC 6820Address Resolution Problems in Large Data Center NetworksCurrent
January 2013
- RFC 9762Using Router Advertisements to Signal the Availability of DHCPv6 Prefix Delegation to ClientsCurrent
June 2025
- RFC 9010Routing for RPL (Routing Protocol for Low-Power and Lossy Networks) LeavesUpdated
April 2021
- RFC 6494Certificate Profile and Certificate Management for SEcure Neighbor Discovery (SEND)Current
February 2012
- RFC 6059Simple Procedures for Detecting Network Attachment in IPv6Current
November 2010
- RFC 5175IPv6 Router Advertisement Flags OptionCurrent
March 2008
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?