NET-IPV6-029 - IPv6 Multicast Source ADDR are not blocked - 'deny ipv6 any ff00::/16 log'

Information

The network device must block IPv6 multicast addresses used as a source address.

IPv6 multicast addresses should never be a source address. They should only be destination addresses.

NOTE: Change 'IPV6_INGRESS_ACL' to the access control list for IPv6 inbound connection filtering.

Solution

Configure the perimeter router access control lists to deny any IPv6 multicast address used as a source address.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, Rule-ID|SV-15407r3_rule, STIG-ID|NET-IPV6-029, Vuln-ID|V-14697

Plugin: Cisco

Control ID: aa2a896e38cdb12617bdc8c03f5978036df4ddfb637ba8f8e22bbd51e39888f1