IPv6 Neighbor Discovery

Neighbor discovery works over the ICMPv6 Neighbor Discovery protocol, which is the functional equivalent of the IPv4 ARP protocol.

ICMPv6 Neighbor Discovery Protocol must be explicitly permitted in the Access Control Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase. for all bridged networks.

This is different from ARP. ARP traffic is Layer 2 only, therefore it permitted regardless of the RuleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. Base.

This is an example of an explicit Rule Base that permits ICMPv6 Neighbor Discovery protocol:

Name

Source

Destination

VPN

Services & Applications

Action

Track

Install On

IPv6

Neighbor

Discovery

Network object

that represents

the Bridged

Network

Network object

that represents

the Bridged

Network

Any

neighbor-advertisement

neighbor-solicitation

router-advertisement

router-solicitation

redirect6

Accept

Log

Policy Targets