Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Скачиваний:
51
Добавлен:
11.04.2015
Размер:
22.9 Mб
Скачать

Chapter 15

IPv6 Security Considerations

At the end of this chapter, you should be able to do the following:

Describe how to prevent unauthorized hosts from obtaining automatic Internet Protocol version 6 (IPv6) configuration.

Describe how to provide protection for IPv6 packets.

Describe how to protect IPv6 hosts from address and port scanning attacks.

Describe how to control what traffic is exchanged with the Internet.

IPv6 Security Considerations

Before deploying IPv6 you should be aware of the following aspects of security for IPv6 traffic:

Authorization for automatically assigned addresses and configurations

Protection of IPv6 packets

Host protection from scanning and attacks

Control of what traffic is exchanged with the Internet

The following sections describe each of these aspects of security and provide recommendations and best practices for computers running Windows Server 2008 or Windows Vista.

Authorization for Automatically Assigned Addresses and Configurations

After gaining access to an intranet, any computer can obtain a valid IPv6 address configuration through stateless or stateful address autoconfiguration and begin communicating on the network. IPv6 hosts can use the following methods to obtain an address configuration:

Neighbor Discovery (ND) with an exchange of Router Solicitation and Router Advertisement messages, as defined in RFC 4861

Dynamic Host Configuration Protocol for IPv6 (DHCPv6), as defined in RFC 3315 For more information about ND and DHCPv6, see Chapter 8, “Address Autoconfiguration.”

For ND-based IPv6 configuration, SEcure Neighbor Discovery (SEND) (defined in RFC 3971) can provide protection for Router Solicitation and Router Advertisement messages. SEND can also provide protection for Neighbor Solicitation and Neighbor Advertisement message exchanges for address resolution or neighbor unreachability detection. This provides

355

Соседние файлы в папке Lecture 2_10