Skip to main content
PacketMentor logo
Open menu
← All topics
Security Fundamentals Foundational

IPv6 RA Guard

What IPv6 RA Guard does, why it matters, and the one-command Cisco IOS config. Covers CCNA 200-301 v2.0 objective 4.7.d.

Quick summary
  • Rogue Router Advertisements can hijack IPv6 hosts the same way rogue DHCP can hijack IPv4. RA Guard blocks RAs on ports where they should not appear.
  • You apply RA Guard on access ports (toward PCs). Trusted ports (toward real routers) keep forwarding RAs.
  • One-command style on Cisco IOS: ipv6 nd raguard attach-policy HOST on the access interface.

Mental model

IPv6 hosts learn their gateway from Router Advertisement (RA) messages — the IPv6 version of “where’s the gateway.” Any device on the LAN can send one. A laptop running Linux with IPv6 forwarding on, a Windows PC accidentally sharing an internet connection, or an attacker, can start sending RAs. Hosts believe it. Traffic goes to the wrong place.

RA Guard is the fix. It is the IPv6 cousin of DHCP Snooping: on each access port, you declare whether RAs are allowed. If an RA arrives on a port that should never see one, the switch drops it.

When to apply

Port roleRA Guard policy
Access port (PC, printer, phone, AP)Block all RAs
Trunk / uplink to a real routerAllow RAs

Keep it simple: trust uplinks, block access ports.

Cisco IOS config

ipv6 nd raguard policy HOST
 device-role host

interface range Gi1/0/1 - 24
 ipv6 nd raguard attach-policy HOST
  • device-role host means “this port leads to hosts, so no RAs allowed.”
  • Attach the policy to every access interface.
  • Uplinks toward routers get no policy (or a policy with device-role router).

Verify

show ipv6 snooping policies
show ipv6 nd raguard policy HOST

Watch the drop counter rise when a rogue RA is sent.

Common gotchas

  • IPv6 is enabled by default on modern Windows / macOS / Linux. You cannot opt out of RA Guard just because “we don’t run IPv6” — you still run IPv6, you just do not notice.
  • Trunks need the right policy, not no policy. A policy of device-role router on the uplink keeps the trunk working.
  • DAI protects IPv4, RA Guard protects IPv6. You need both on the same switch.
  • First-hop security = RA Guard + ND inspection + IPv6 source guard. CCNA v2.0 lists RA Guard only, but the full set is one feature family.

FAQ

Does RA Guard replace DHCPv6 snooping? No, they are different. RA Guard blocks rogue gateway advertisements. DHCPv6 Guard blocks rogue DHCPv6 servers handing out addresses. Many networks run both.

Is RA Guard on by default? No. You must apply a policy to each access interface.

Why not just disable IPv6 on PCs? Modern operating systems do not support disabling IPv6 cleanly. Microsoft and Apple ship IPv6-enabled by design. The right answer is to defend the LAN, not to disable the protocol.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on IPv6 RA Guard. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where IPv6 RA Guard fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.