Hi,
on the [ipv6-ops] mailing list currently there’s some discussion about RA guard support on switches from different vendors.
Stefan, one of our students (btw: working on a topic similar to this session), quickly put together a preliminary list, based on publicly available information (read: the WWW ;-)). Some of you may find this useful; it can be found here. Furthermore on the list this link was mentioned which seems to provide some info as well (albeit potentially not very up-to-date).
If anyone of you has better/more information pls feel free to share by leaving a comment. The IPv6 security comment will thank you for that
Best
Enno
If someone is doing further research on this topic it would be interesting to see which switches can detect and/or drop fragmented Router Advertisements. That is currently a common way of evade RA Guard.
Thanks for the list Enno!
Regards, W.
The HP list doesn’t look particularly accurate. The 2910 definitely does RA guard – you can confirm in these release notes:
http://h20000.www2.hp.com/bc/docs/support/SupportManual/c03467132/c03467132.pdf
I’m relatively sure the 2920 does too.
It would be worth adding extreme networks devices to the list too.