摘要 |
In one embodiment, a particular device (e.g., switch) receives a neighbor discovery (ND) message from a non-trusted non-switch device, the ND message having an associated address, and creates a corresponding binding entry for the address in a temporary tentative state without forwarding the ND message. In addition, the switch then generates and forwards a first duplicate address detection (DAD) message on behalf of the non-trusted non-switch device. In response to receiving a second DAD message from a non-owner device, the switch may either drop the second DAD message when a corresponding second address of the second DAD message is stored as a tentative-state entry, or else forward the second DAD message to a corresponding owner device of the second address for neighbor advertisement (NA) defense when the second address is not stored as a tentative-state entry.
|