AdvancedPublished 2026-08-21
CCNA Foundations: IPv6 RA Guard — Trust One Router
Archive lab
Harden a dual-stack access segment with IPv6 RA Guard so only the legitimate router can advertise a default gateway. You will start from a working IPv4 baseline with IPv6 SLAAC enabled, then implement and verify RA Guard on the access switch. The solution must keep end-to-end IPv4/IPv6 reachability while blocking rogue Router Advertisements from a malicious host.
Learning objectives
- Explain how IPv6 Router Advertisements (RA) create default routes via SLAAC and why they must be protected on access segments
- Configure an IPv6 ND RA Guard policy on an IOSv-L2 access switch
- Apply the RA Guard policy to host-facing access ports while leaving the uplink to the router trusted
- Verify client SLAAC behavior and end-to-end IPv6 reachability with RA Guard in place
- Use show commands to confirm RA Guard policy status and counters
Troubleshooting focus
- Clients do not autoconfigure IPv6: confirm the gateway interface is in the correct VLAN and is sending RAs; verify RA Guard is not attached to the router-facing uplink
- IPv6 works on some ports but not others: check which ports have the RA Guard policy attached and that host ports are in the user VLAN
- IPv4 works but IPv6 fails: confirm static IPv6 routes on the routers and that the client received a default route from the gateway
- RA Guard counters remain zero: ensure traffic is actually present; test by observing SLAAC and checking show commands on the switch
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.