RA Guard DHCP Guard Pattern Possible Enhancement
Sigmond Axel <[email protected]> Sat, 27 Jun 2026 17:25:02 -0500
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
Greetings, There is this old greeting format where one leg is placed = forward and a formal full body bow is then initiated. Required by = royalty 100 years ago for greeting and respect. Virtually extending that = now=E2=80=A6 =20 Problem: A broadcast can come from anywhere to request a change an = existing RA ipv6, or DHCP ipv4 important configs. The reply is = initiated by a client in both cases. The first reply is the trusted one. = The reply broadcast contains the MAC address and the ip of the = responder. This can be stored in a tuple set for future reference. The = problem comes about when there is no proper way to test if the set if it = is empty. The set is set at size 1 tuple set with ip address and MAC, = once populated with the trusted value the client will initiate a renewal = and can reset the tuple set on the next reply=20 The RA Guard and DHCP guard have the same pattern also DHCPv6 too. = There may be something I am over looking. Maybe a null set setting. = Could be a very simple and useful enhancement. Or something I am over = looking. Sigi.=20=