Mental model
IPv6 hosts learn their gateway from Router Advertisement (RA) messages — the IPv6 version of “where’s the gateway.” Any device on the LAN can send one. A laptop running Linux with IPv6 forwarding on, a Windows PC accidentally sharing an internet connection, or an attacker, can start sending RAs. Hosts believe it. Traffic goes to the wrong place.
RA Guard is the fix. It is the IPv6 cousin of DHCP Snooping: on each access port, you declare whether RAs are allowed. If an RA arrives on a port that should never see one, the switch drops it.
When to apply
| Port role | RA Guard policy |
|---|---|
| Access port (PC, printer, phone, AP) | Block all RAs |
| Trunk / uplink to a real router | Allow RAs |
Keep it simple: trust uplinks, block access ports.
Cisco IOS config
ipv6 nd raguard policy HOST
device-role host
interface range Gi1/0/1 - 24
ipv6 nd raguard attach-policy HOST
device-role hostmeans “this port leads to hosts, so no RAs allowed.”- Attach the policy to every access interface.
- Uplinks toward routers get no policy (or a policy with
device-role router).
Verify
show ipv6 snooping policies
show ipv6 nd raguard policy HOST
Watch the drop counter rise when a rogue RA is sent.
Common gotchas
- IPv6 is enabled by default on modern Windows / macOS / Linux. You cannot opt out of RA Guard just because “we don’t run IPv6” — you still run IPv6, you just do not notice.
- Trunks need the right policy, not no policy. A policy of
device-role routeron the uplink keeps the trunk working. - DAI protects IPv4, RA Guard protects IPv6. You need both on the same switch.
- First-hop security = RA Guard + ND inspection + IPv6 source guard. CCNA v2.0 lists RA Guard only, but the full set is one feature family.
FAQ
Does RA Guard replace DHCPv6 snooping? No, they are different. RA Guard blocks rogue gateway advertisements. DHCPv6 Guard blocks rogue DHCPv6 servers handing out addresses. Many networks run both.
Is RA Guard on by default? No. You must apply a policy to each access interface.
Why not just disable IPv6 on PCs? Modern operating systems do not support disabling IPv6 cleanly. Microsoft and Apple ship IPv6-enabled by design. The right answer is to defend the LAN, not to disable the protocol.
