NET-IPV6-029 - IPv6 Multicast Source ADDR are not blocked - 'deny ipv6 any ff00::/16 log'

Information

The network device must block IPv6 multicast addresses used as a source address.

IPv6 multicast addresses should never be a source address. They should only be destination addresses.

NOTE: Change 'IPV6_INGRESS_ACL' to the access control list for IPv6 inbound connection filtering.

Solution

Configure the perimeter router access control lists to deny any IPv6 multicast address used as a source address.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, Rule-ID|SV-15407r3_rule, STIG-ID|NET-IPV6-029, Vuln-ID|V-14697

Plugin: Cisco

Control ID: 6587aa50e6f1161de5ad61fcfd2d1fe91775a434b4ec62a7851fa02ef5409a19