IPv6 Neighbor Discovery Protocol (NDP) (RFC 4861) has a number of security issue which should be considered when deploying the protocol. On Oct 2nd, CERT/CC will be publishing a "Vulnerability Note" (VU#472363) on one of several known and documented issues with IPv6 NDP titled IPv6 NDP Routing Vulnerability.
JUNOS's current implementation of IPv6 Neighbor Discovery Protocol (NDP) allows a directly connected node to spoof and insert a off-link IPv6 address into the router's forwarding table. This exposes the nodes directly connected to the router to the equivalent of IPv4 ARP Spoofing - allowing another node to pretend to be another node. Like ARP Spoofing, this exposure allows the attacker to execute man-in-the-middle, DOS, or hijacking attacks.
This behavior was added to JUNOS to comply with strict RFC behavior requirements during the IPv6 Forum's certification test .
JUNOSe and ScreenOS implementations are not exposed to this issue.
We would like to thank David Miles for validating and reporting this issue to Juniper and other CSIRT agencies.
CVE Name: CVE-2008-2476
Juniper has added new configuration option for the IPv6 Neighbor Discovery Protocol (NDP). This option will not allow a "Neighbor Solicitation (NS) from a prefix which was not covered under one of our interface prefixes see RFC (4861 7.2.3)." The new command isset protocol neighbor-discovery onlink-subnet-only
Note: The RE needs to be reloaded after setting this knob to remove the any possibility of a malicious IPv6 entry from the forwarding-table.A review RFC 3756 "IPv6 Neighbor Discovery (ND) Trust Models and Threats" would help operators understand the range of risk with IPv6 Neighbor Discovery.
Today, IPv6 Unicast Reverse Path Forwarding (RPF) is a highly effective mitigation tool for this security risk.