← All lab tasks Security Fundamentals Fix · Medium ~15 min · 4 devices · 5 tasks · CCNA v2.0
IPv6 RA Guard: block a rogue router advertisement on access ports A user on PC1 plugged a travel router (ROGUE) into Fa0/5 to extend their desk. The travel router sends unsolicited IPv6 Router Advertisements and PC1 is now using it as the IPv6 default gateway, which breaks everything that is not local to that subnet. The real router R-REAL is on Gi0/23 and is the only device that should send RAs. Enable IPv6 RA Guard on SW1 so only the uplink to R-REAL is allowed to source RAs. Clients plug into Fa0/1 through Fa0/10.
SW1 Gi0/23 -> R-REAL (real IPv6 router, 2001:db8:a::1/64) SW1 Fa0/1 -> PC1 (victim) SW1 Fa0/5 -> ROGUE (travel router sending bad RAs) Access ports in VLAN 10 (prefix 2001:db8:a::/64)
Tasks ○ Create an RA Guard policy HOST-PORTS with device-role host ○ Create an RA Guard policy ROUTER-UPLINK with device-role router ○ Apply HOST-PORTS policy to Fa0/1 (and ideally all access ports) ○ Apply HOST-PORTS policy to Fa0/5 (the rogue port) ○ Apply ROUTER-UPLINK policy to Gi0/23 (the real router port) ✓ Network fixed.
RAs from Fa0/5 are now dropped. Only R-REAL on Gi0/23 can advertise an IPv6 default gateway on this VLAN.
Hints (open one at a time) Hint 1: the global command RA Guard is applied via a policy. Start with ipv6 nd raguard policy HOST-PORTS, then set device-role host. Repeat for ROUTER-UPLINK with device-role router.
Hint 2: applying the policy Enter interface config and apply with ipv6 nd raguard attach-policy HOST-PORTS. Access ports get HOST-PORTS, the trunk or router uplink gets ROUTER-UPLINK.
Hint 3: verify Run show ipv6 nd raguard policy HOST-PORTS to confirm it is attached to the right interfaces. From the client, show ipv6 routers should list only R-REAL after a brief wait.
Full solution SW1# configure terminal
SW1(config)# ipv6 nd raguard policy HOST-PORTS
SW1(config-nd-raguard)# device-role host
SW1(config-nd-raguard)# exit
SW1(config)# ipv6 nd raguard policy ROUTER-UPLINK
SW1(config-nd-raguard)# device-role router
SW1(config-nd-raguard)# exit
SW1(config)# interface range Fa0/1 - 10
SW1(config-if-range)# ipv6 nd raguard attach-policy HOST-PORTS
SW1(config-if-range)# exit
SW1(config)# interface GigabitEthernet0/23
SW1(config-if)# ipv6 nd raguard attach-policy ROUTER-UPLINK
SW1(config-if)# endRA Guard is a Layer 2 first-hop security feature. It inspects ICMPv6 RA messages at the switchport and drops them when the port's role does not allow it.