Elective Advanced Networking with IPv6

Advanced Networking with IPv6Unit 38 min read

ICMPv6 & Neighbor Discovery: Packets, Discovery & Security

Unit 3 of Advanced Networking with IPv6 explores ICMPv6’s role in IPv6 communication, its packet types (Echo Request/Reply, Router Solicitation, etc.), and Neighbor Discovery Protocol (NDP) for address autoconfiguration, duplicate address detection, and router discovery. It contrasts ICMPv6 with ICMPv4, analyzes NDP me

ICMPv6: The Swiss Army Knife of IPv6 Communication

What is ICMPv6?

ICMPv6 (Internet Control Message Protocol for IPv6) is the error-reporting and discovery protocol for IPv6 networks. Unlike ICMPv4, it is mandatory for all IPv6 nodes and handles:

  • Error messages (e.g., "Destination Unreachable")
  • Diagnostic tools (e.g., ping6, traceroute6)
  • Neighbor Discovery (NDP) messages (a subset of ICMPv6)

How ICMPv6 Packets Work: A Deep Dive

ICMPv6 messages are carried as payloads in IPv6 packets (unlike ICMPv4, which uses IP). Key fields:

  • Type (8 bits): Identifies the message (e.g., 128 = Echo Request).
  • Code (8 bits): Subtype (e.g., 0 = "No route to destination").
  • Checksum (16 bits): Ensures integrity (unlike ICMPv4, which has no checksum in IPv6).
  • Payload: Varies by message (e.g., Echo Request includes an identifier and sequence number).

Worked Example: ping6 in Action

When you run ping6 google.com:

  1. Your host sends an Echo Request (Type 128) to Google’s IPv6 address (2607:f8b0:4009:80e::200e).
  2. Google’s router forwards it to the target server.
  3. The server replies with an Echo Reply (Type 129), including the original payload.
  4. Your host calculates Round-Trip Time (RTT) and displays it.
sequenceDiagram
    participant Host as Your PC (IPv6)
    participant Router as ISP Router
    participant Server as Google Server
    Host->>Router: Echo Request (Type 128) to 2607:f8b0:4009:80e::200e
    Router->>Server: Forwarded Echo Request
    Server-->>Router: Echo Reply (Type 129)
    Router-->>Host: Echo Reply
    note over Host: RTT = 25ms

Real-World Tie-In:

  • eSewa’s IPv6 Transactions: When you pay a bill via eSewa, the app uses ping6 to verify connectivity to the bank’s IPv6 gateway before processing the payment. A failed Echo Reply could mean a network outage, triggering a retry or error message.

Neighbor Discovery Protocol (NDP): IPv6’s Auto-Configuration Toolkit

NDP replaces ARP, ICMP Router Discovery, and ICMP Redirect from IPv4. It runs over ICMPv6 and performs four critical functions:

1. Router Discovery

  • Router Solicitation (RS): Sent by hosts to ask, "Who’s the router?"
  • Router Advertisement (RA): Sent by routers to announce their presence, prefix, and other config (e.g., MTU, hop limit).
Router Solicitation (Type 133)Router Advertisement (Type 134)HostRouter
Router Discovery exchange: Host solicits (RS) and Router advertises (RA) with prefix 2001:db8::/64

2. Address Autoconfiguration (SLAAC)

  • Hosts generate a link-local address (e.g., fe80::1234:5678:9abc:def0) and a global address using the router’s prefix (e.g., 2001:db8::1234:5678:9abc:def0).
  • No DHCP needed for basic config (though DHCPv6 can still be used for extra options).

3. Duplicate Address Detection (DAD)

  • Before using an address, a host sends a Neighbor Solicitation (NS) to check if it’s already in use.
  • If another node replies with a Neighbor Advertisement (NA), the address is a duplicate.
sequenceDiagram
    participant HostA as New Host (fe80::1)
    participant HostB as Existing Host (fe80::1)
    HostA->>HostB: Neighbor Solicitation (NS) for fe80::1
    HostB-->>HostA: Neighbor Advertisement (NA)
    note over HostA: Aborts address use!

4. Neighbor Unreachability Detection (NUD)

  • Detects if a neighbor (e.g., router or server) is still reachable.
  • Uses NS/NA exchanges to probe connectivity.

NDP vs. IPv4 Protocols: A Comparison Table

Function IPv4 Protocols IPv6 (NDP)
ARP Resolves IP → MAC Replaced by NS/NA
ICMP Router Discovery Router Discovery messages Router Solicitation/Advertisement
ICMP Redirect Optimizes routing paths Redirect message (Type 137)
DHCP Configures IP, subnet mask, gateway SLAAC (no DHCP for basic config)
Manual Config ipconfig /all ipconfig /all (but SLAAC preferred)

Security in ICMPv6 and NDP

ApplicationDataTransportSegmentNetworkPacketData LinkFrame
ICMPv6’s position in the OSI model

Threats in ICMPv6/NDP

  1. Spoofed Router Advertisements: Attackers send fake RAs to redirect traffic (e.g., Man-in-the-Middle).
  2. Neighbor Cache Poisoning: Fake NS/NA messages trick hosts into updating their neighbor tables incorrectly.
  3. Amplification Attacks: ICMPv6 messages can be spoofed to flood targets (e.g., DDoS).

Mitigations

  • Secure Neighbor Discovery (SEND): Uses cryptographic signatures (e.g., RSA) to authenticate RAs.
  • Router Preference: Hosts prefer RAs from trusted routers (e.g., higher Router Preference value).
  • Firewall Rules: Block unsolicited NS/NA messages.

Real-World Example:

  • Ncell’s IPv6 Rollout: Ncell uses SEND-like mechanisms to prevent spoofed RAs in its 4G/5G networks. When your phone connects to an IPv6-enabled tower, it verifies the RA’s signature before accepting routing info.

Worked Example: Tracing an IPv6 Path with ICMPv6

Scenario: You’re debugging why your ping6 to ipv6.google.com fails. Use traceroute6 to trace the path.

  1. Command:
    traceroute6 ipv6.google.com
    
  2. Output Interpretation:
    1  fe80::1 (Your router) - 1ms
    2  2001:db8:1::1 (ISP Router) - 10ms
    3  2001:db8:2::1 (Google Edge Router) - 25ms
    4  2001:db8:3::1 (Google Server) - 30ms
    
  3. Analysis:
    • Hop 2 (ISP Router): High latency → Possible congestion.
    • Hop 4: Final server → If this fails, it’s a Google-side issue.

Why This Matters:

  • Pathao’s Ride Dispatch: Pathao’s servers use traceroute6 to monitor IPv6 paths between driver apps and central dispatchers. If a hop fails, they reroute via a backup ISP (e.g., NTC or Smart).

In the Real World

  1. eSewa’s IPv6 Transactions

    • Idea Used: ICMPv6 Echo Request/Reply for connectivity checks.
    • How: Before processing a payment, eSewa’s backend sends ping6 to the bank’s IPv6 gateway (2001:4860:4860::8888). If the Echo Reply fails, it retries or shows an error.
  2. Ncell’s IPv6 4G/5G Networks

    • Idea Used: Router Advertisements (RA) for autoconfiguration.
    • How: Your phone receives RAs from Ncell’s towers to auto-configure an IPv6 address (e.g., 2402:8100:1234:5678::1). This eliminates manual DHCP and speeds up connection.
  3. Daraz’s IPv6 Order Fulfillment

    • Idea Used: Neighbor Discovery (NS/NA) for MAC resolution.
    • How: When your order is processed, Daraz’s servers use NS/NA to resolve the MAC of the warehouse’s IPv6-enabled printer (which labels packages). If the printer’s MAC isn’t in the cache, an NS is sent to discover it.

Exam Tip

What to Expect in TU/PU Exams

  1. Packet Analysis: Draw and label an ICMPv6 packet (e.g., Echo Request with payload).
  2. NDP Scenarios: Explain how a host gets its IPv6 address using SLAAC + DAD (with NS/NA exchanges).
  3. Comparisons: Contrast ICMPv4 vs. ICMPv6 (e.g., checksum, fragmentation, mandatory status).
  4. Security: Describe one attack (e.g., spoofed RA) and its mitigation (e.g., SEND).
  5. Troubleshooting: Given a ping6 failure, diagnose using traceroute6 (e.g., "Hop 3 is down → ISP issue").

Common Pitfalls:

  • Forgetting that ICMPv6 has no fragmentation (unlike ICMPv4).
  • Confusing Router Solicitation (RS) with Neighbor Solicitation (NS).
  • Ignoring link-local addresses (e.g., fe80::/10) in NDP.

Pro Tip:

  • Memorize the NDP message types (RS, RA, NS, NA, Redirect) and their Type/Code values (e.g., RA = Type 134).
  • Practice drawing sequence diagrams for NDP exchanges—they’re high-value in exams!

Based on the TU BSc CSIT syllabus for Advanced Networking with IPv6, unit 3.

Discussion

Loading…