当前位置:首页 > 报告详情

具有第一跳安全性的本地 IPv6 安全性.pdf

上传人: 2*** 编号:138784 2023-06-03 65页 2.75MB

1、#CiscoLive#CiscoLiveric Vyncke,Distinguished EngineerevynckeBRKENT-3002IPv6 Security in the IPv6 Security in the Local Area with First Local Area with First Hop Security(FHS)Hop Security(FHS)2023 Cisco and/or its affiliates.All rights reserved.Cisco Public#CiscoLiveSession Objectives(from the Abstra

2、ct)A big difference in the security between IPv4 and IPv6 is all the layer-2/layer-3 interactions as DHCP is optional in IPv6 and ARP is replaced by Neighbour Discovery Protocol(NDP).Legacy IPv4 attacks such as ARP spoofing have their equivalent in IPv6.Cisco has developed for many years techniques

3、to secure this interaction in the local area(being WLAN,LAN,SD-Access,Meraki,ACI,etc).This session explains what are the attacks and how Cisco can protect your networks.BRKENT-30024 2023 Cisco and/or its affiliates.All rights reserved.Cisco Public#CiscoLiveEnter your personal notes hereCisco Webex A

4、pp Questions?Use Cisco Webex App to chat with the speaker after the sessionFind this session in the Cisco Live Mobile AppClick“Join the Discussion”Install the Webex App or go directly to the Webex spaceEnter messages/questions in the Webex spaceHowWebex spaces will be moderated by the speaker until

5、June 9,2023.12346https:/ 2023 Cisco and/or its affiliates.All rights reserved.Cisco PublicBRKENT-30026#CiscoLive 2023 Cisco and/or its affiliates.All rights reserved.Cisco PublicAgendaSecuring StateLess Address Auto-Configuration(SLAAC)Integrity of Addresses BindingsAddress AvailabilityMore Informat

6、ion on First Hop Security(FHS)FHS in a SD-Access FabricIPv6 Security Beyond Local AreaSummaryKnowledge of IPv6,NDP,fragmentation,network security is assumed BRKENT-30027Securing StateLessAddress Auto-Configuration(SLAAC)2023 Cisco and/or its affiliates.All rights reserved.Cisco Public#CiscoLiveState

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了IPv6在本地区域的安全问题,特别是第一跳安全(FHS)的策略。主要内容包括: 1. IPv6与IPv4在安全性上的主要区别在于层2/层3的交互,如DHCP在IPv6中是可选的,而ARP被邻居发现协议(NDP)所取代。 2. 一些在IPv4中常见的攻击,如ARP欺骗,在IPv6中也有对应的形式。Cisco开发了多种技术来保护本地区域(如WLAN、LAN、SD-Access、Meraki、ACI等)中的这些交互。 3. 文章详细解释了各种攻击手段以及Cisco如何保护网络。包括保护无状态地址自动配置(SLAAC)、保护MAC-IPv6地址绑定、地址可用性等。 4. 文章还介绍了FHS在SD-Access网络中的运用,以及IPv6安全在本地区域之外的扩展。 5. 最后,文章总结了IPv6与IPv4在安全性上的差异,以及如何通过FHS来保护IPv6网络。
如何在IPv6中保护网络免受ARP欺骗攻击? 如何确保IPv6地址与MAC地址绑定的一致性? 如何防止IPv6地址初始化过程中的拒绝服务攻击?
客服
商务合作
小程序
服务号
折叠