RA Guard DHCP Guard Pattern Possible Enhancement

Sigmond Axel <[email protected]> Sat, 27 Jun 2026 17:25:02 -0500
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
Greetings,  There is this old greeting format where one leg is placed =
forward and a formal full body bow is then initiated. Required by =
royalty 100 years ago for greeting and respect. Virtually extending that =
now=E2=80=A6  =20

Problem:   A broadcast can come from anywhere to request a change an =
existing RA ipv6, or DHCP ipv4 important configs.  The reply is =
initiated by a client in both cases. The first reply is the trusted one. =
The reply broadcast contains the MAC address and the ip of the =
responder.  This can be stored in a tuple set for future reference.  The =
problem comes about when there is no proper way to test if the set if it =
is empty.  The set is set at size 1 tuple set with ip address and MAC, =
once populated with the trusted value the client will initiate a renewal =
and can reset the tuple set on the next reply=20

The RA Guard and DHCP guard have the same pattern also DHCPv6 too.  =
There may be something I am over looking. Maybe a  null set setting. =
Could be a very simple and useful enhancement.  Or something I am over =
looking.  Sigi.=20=