Web Management Guide-R02

Table Of Contents
Chapter 12
| Security Measures
ND Snooping
– 379 –
Figure 237: Displaying Statistics for DHCPv6 Snooping
ND Snooping
Neighbor Discovery (ND) Snooping maintains an IPv6 prefix table and user address
binding table. These tables can be used for stateless address auto-configuration or
for address filtering by IPv6 Source Guard.
ND snooping maintains a binding table in the process of neighbor discovery. When
it receives an Neighbor Solicitation (NS) packet from a host, it creates a new
binding. If it subsequently receives a Neighbor Advertisement (NA) packet, this
means that the address is already being used by another host, and the binding is
therefore deleted. If it does not receive an NA packet after a timeout period, the
binding will be bound to the original host. ND snooping can also maintain a prefix
table used for stateless address auto-configuration by monitoring Router
Advertisement (RA) packets sent from neighboring routers.
ND snooping can also detect if an IPv6 address binding is no longer valid. When a
binding has been timed out, it checks to see if the host still exists by sending an NS
packet to the target host. If it receives an NA packet in response, it knows that the
target still exists and updates the lifetime of the binding; otherwise, it deletes the
binding.
Usage Guidelines
ND snooping must be enabled globally on the switch and on a specific VLAN or
a range of VLANs.
Once ND snooping is enabled both globally and on the required VLANs, the
switch will start monitoring RA messages to build an address prefix table as
described below: