
Advanced IPv6 Vulnerability Analysis, Security Testing, Attack Recognition, and Mitigation
2-Day Instructor-Led Hands-On Lab Course
Available in Web-Based or On-Site delivery.
Minimum 10 students – Maximum 16 students
Course Description
IPv6 security requires more than applying existing IPv4 security practices to a larger address space.
IPv6 introduces protocol behaviors, control messages, addressing methods, Extension Headers, host-configuration mechanisms, and first-hop interactions that create their own security considerations. Network and security professionals responsible for IPv6 environments must understand not only the intended operation of these mechanisms, but how they can be abused, manipulated, misconfigured, or incorrectly processed.
Hands-On Advanced IPv6 Security is an intensive two-day course designed specifically for networking professionals who already possess strong IPv6 skills.
This is not an IPv6 fundamentals course. Students are expected to arrive already comfortable with IPv6 addressing, ICMPv6, Neighbor Discovery, Router Advertisements, SLAAC, DHCPv6, IPv6 routing, and IPv6 packet analysis.
The course instead focuses on the security implications of IPv6 operation.
Students use a controlled laboratory environment to examine specific IPv6 attack techniques and vulnerabilities. They generate test traffic, observe system and network behavior, analyze packet captures, determine the impact of the activity, and relate what they observe to appropriate security controls and mitigation strategies.
The emphasis is on understanding what actually happens on the network.
Students are encouraged to distinguish among:
- Expected IPv6 protocol behavior
- Security-sensitive protocol behavior
- Configuration weaknesses
- Implementation weaknesses
- Security-control limitations
- Attack activity
- Observable packet evidence
The objective is not merely to learn that an IPv6 vulnerability exists.
The objective is to understand how to recognize it, test for it in an authorized environment, observe its effects, and evaluate the protections intended to mitigate it.
Course Positioning
This course is intentionally specialized.
IPv6 addressing fundamentals, SLAAC, Neighbor Discovery fundamentals, DHCPv6 operation, IPv6 routing, and general IPv6 troubleshooting are covered in CellStream’s prerequisite IPv6 courses and are not repeated here.
The two days are reserved for advanced IPv6 security analysis and the existing hands-on security laboratory exercises.
Course Objectives
Upon completion of this course, students will be able to:
- Explain why IPv6 security cannot be approached simply as IPv4 security with 128-bit addresses.
- Identify important IPv6 protocol behaviors that create security exposure.
- Distinguish protocol vulnerabilities from configuration and implementation weaknesses.
- Perform authorized IPv6 security testing in a controlled laboratory environment.
- Analyze attacks involving ICMPv6.
- Evaluate security issues involving IPv6 per-hop processing.
- Examine security issues associated with IPv6 addressing and host discovery.
- Analyze the security implications of IPv6 Extension Headers.
- Examine DHCPv6 attack scenarios and rogue DHCPv6 behavior.
- Recognize additional IPv6 attack and vulnerability patterns.
- Use packet captures to identify evidence associated with IPv6 security events.
- Evaluate how IPv6 packets are processed by hosts, routers, switches, and security devices.
- Determine whether a security mechanism actually mitigates the condition it is intended to prevent.
- Separate observed evidence from assumptions during security analysis.
- Develop appropriate mitigation and defensive recommendations based on laboratory findings.
- Apply a systematic methodology to IPv6 security assessment and validation.
Audience
This is an advanced technical course intended for personnel responsible for the security, engineering, testing, or operation of IPv6 networks.
Ideal participants include:
- Network Security Engineers
- Network Engineers
- Service Provider Engineers
- Broadband Network Engineers
- Network Architects
- Security Architects
- Network Operations personnel
- Security Operations personnel
- Network Administrators
- Product Engineers
- Systems Engineers
- Test Engineers
- Network Security Test personnel
- Technical Support Engineers
- Network Management personnel
- Technical personnel responsible for validating IPv6 products or services
The course is particularly valuable for professionals who need to understand how IPv6 behaves when subjected to malformed, manipulated, unexpected, or hostile network traffic.
Prerequisites
This is an advanced IPv6 course.
Students should have successfully completed one of the following CellStream courses before attending:
Equivalent advanced hands-on IPv6 experience may be accepted where appropriate.
Students are expected to already understand:
- IPv6 addressing and prefix notation
- Link-Local and Global Unicast addressing
- IPv6 multicast
- ICMPv6
- Neighbor Discovery
- Neighbor Solicitation and Neighbor Advertisement
- Router Solicitation and Router Advertisement
- SLAAC
- DHCPv6
- IPv6 routing
- Basic IPv6 Extension Header concepts
- IPv6 packet capture and analysis
These subjects will not be retaught as fundamentals during this course.
Students should also be comfortable working from a command line and analyzing packets with Wireshark or similar packet-analysis tools.
Students must have access to a computer capable of running the software and Linux-based environment required by the course laboratory exercises. When appropriate classroom systems are provided, a separate student computer may not be required.
Course Materials
Students receive:
- Course Student Guide
- Access to the security laboratory environment
- Required course laboratory resources
- IPv6 packet captures
- Supporting security references
The laboratory exercises are a central component of the course and are designed to provide controlled, repeatable demonstrations of specific IPv6 security behaviors.
Course Outline
Section 1: Course Introduction and Security Lab Methodology
The course begins by establishing the methodology that will be used throughout the two days.
Rather than reviewing IPv6 fundamentals, students prepare to analyze IPv6 from a security perspective.
Topics include:
- Course objectives and laboratory environment
- Authorized security testing
- Establishing expected network behavior
- Establishing a known-good baseline
- Introducing a controlled attack or test condition
- Capturing resulting network traffic
- Comparing normal and abnormal behavior
- Identifying evidence of impact
- Evaluating defensive controls
- Verifying mitigation
A recurring methodology throughout the course is:
Baseline → Test → Observe → Capture → Analyze → Mitigate → Verify
Section 2: IPv6 Security Concepts and Threat Model
This section establishes the security framework for the remainder of the course without repeating IPv6 fundamentals.
Topics include:
- IPv6 security assumptions
- Is IPv6 inherently more secure than IPv4?
- IPv6 attack surfaces
- Local-link versus routed attack exposure
- Control-plane versus data-plane attacks
- Host-based vulnerabilities
- Network-device vulnerabilities
- Security-device processing
- Protocol behavior versus implementation behavior
- Configuration weaknesses
- First-hop security considerations
- Denial-of-service considerations
- Security visibility
- Packet evidence and security analysis
The goal is to establish how to think about IPv6 security, not to review how IPv6 itself works.
Section 3: Attacking ICMPv6
ICMPv6 is fundamental to IPv6 operation and therefore represents an important area of security analysis.
Students examine security issues associated with ICMPv6 behavior and evaluate how malicious or unexpected ICMPv6 traffic can affect IPv6 systems and networks.
Topics include:
- ICMPv6 as both an operational requirement and an attack surface
- Control-message manipulation
- Local-link attack considerations
- Neighbor Discovery-related attack behavior
- Router Advertisement-related security issues
- Resource-consumption considerations
- Spoofed or unexpected control traffic
- Packet-level indicators
- Filtering considerations
- First-hop security controls
- Validation of defensive mechanisms
The existing ICMPv6 security laboratory exercises remain the hands-on component of this section.
Students use packet captures and system behavior to determine what occurred and what evidence supports that conclusion.
Section 4: Attacking IPv6 Per-Hop Processing
IPv6 packet processing can require intermediate systems to examine or react to information beyond simple destination forwarding.
This creates opportunities to evaluate how routers, hosts, and security devices behave when presented with unusual or deliberately constructed IPv6 traffic.
Topics include:
- IPv6 per-hop processing considerations
- Hop-by-Hop processing
- Resource-consumption concerns
- Processing-path differences
- Network-device behavior
- Security-device behavior
- Control-plane exposure
- Unexpected or abnormal packet processing
- Identifying packet evidence
- Evaluating defensive behavior
The existing per-hop processing laboratory exercises remain unchanged.
The emphasis is on understanding the security implications of the observed behavior rather than reviewing normal IPv6 packet forwarding.
Section 5: Attacking IPv6 Addressing
IPv6’s large address space changes attack and reconnaissance techniques, but it does not eliminate host discovery or addressing-related security concerns.
Students examine IPv6 addressing strictly from a security perspective.
Topics include:
- IPv6 reconnaissance
- Address discovery techniques
- Predictable addressing
- Interface Identifier considerations
- Address scanning assumptions
- Host discovery
- Address information leakage
- Stable versus changing IPv6 addresses
- Privacy considerations
- Address-based security assumptions
- Operational visibility and attribution
- Packet evidence associated with reconnaissance
The existing IPv6 addressing security laboratory exercises remain unchanged.
The objective is not to teach IPv6 addressing again, but to examine how addressing choices can affect security, privacy, reconnaissance, and system exposure.
Section 6: Attacking IPv6 Extension Headers
Extension Headers provide important IPv6 functionality but can also create challenges for packet inspection, filtering, intrusion detection, firewalls, and other security mechanisms.
Students examine how Extension Header processing can affect both network devices and security controls.
Topics include:
- IPv6 Extension Header processing
- Header-chain complexity
- Security-device parsing
- Firewall inspection
- IDS/IPS visibility
- Packet-filtering implications
- Fragmentation interactions
- Security-control evasion considerations
- Resource-consumption issues
- Unexpected or malformed header combinations
- Differences among device implementations
- Packet-level evidence
- Mitigation and filtering considerations
The existing IPv6 Extension Header laboratory exercises remain unchanged.
Students compare what the IPv6 packet contains with what the receiving or intermediate device actually does with that packet.
Section 7: Attacking DHCPv6
DHCPv6 introduces its own trust relationships and attack surfaces within IPv6 networks.
Students examine security issues involving DHCPv6 infrastructure and client behavior.
Topics include:
- DHCPv6 security assumptions
- Client/server trust
- Rogue DHCPv6 servers
- Unauthorized configuration information
- DHCPv6 message manipulation
- Resource-consumption considerations
- First-hop DHCPv6 protection
- DHCPv6 filtering
- DHCPv6-Shield concepts
- Packet-level identification of DHCPv6 security events
- Validation of mitigation mechanisms
The existing DHCPv6 security laboratory exercises remain unchanged.
Students analyze both the attack behavior and the packets necessary to demonstrate what occurred.
Section 8: Other IPv6 Attacks and Vulnerabilities
Not every IPv6 security issue fits neatly into a single protocol category.
This section provides the framework for the additional attack and vulnerability scenarios already included in the course.
Depending upon the laboratory scenario, students may evaluate issues involving:
- Host behavior
- Router behavior
- Local-link attacks
- Control-plane exposure
- Resource exhaustion
- Packet-processing behavior
- Protocol implementation
- Security-device limitations
- Filtering
- Spoofing
- Reconnaissance
- Denial-of-service conditions
- Unexpected IPv6 traffic
The existing laboratory exercises in this section remain unchanged.
The focus remains on observing behavior, identifying evidence, determining impact, and evaluating defenses.
Section 9: Conclusions and References
The course concludes by connecting the individual attack scenarios into a repeatable IPv6 security-assessment methodology.
Students consider:
- What was attacked?
- What protocol behavior made the attack possible?
- Was the issue inherent to the protocol, an implementation, or a configuration?
- What evidence demonstrated the attack?
- What did the packet capture reveal?
- What impact occurred?
- What defensive control should address the problem?
- Did the mitigation actually work?
- How could the activity be detected in an operational network?
Students leave with a framework that can be applied beyond the specific exercises performed during the class:
Understand the behavior.
Test the behavior.
Capture the evidence.
Determine the impact.
Apply the defense.
Verify the result.
Course Outcome
This course does not attempt to make students IPv6 experts.
They are expected to arrive as IPv6 experts.
The purpose of this course is to develop the next level of skill: understanding how IPv6 can be attacked, how those attacks appear on the network, and how IPv6 security controls can be evaluated using actual evidence.
Students leave better prepared to:
Recognize IPv6 vulnerabilities.
Test IPv6 security in an authorized environment.
Analyze attack traffic.
Evaluate defensive controls.
And prove whether those controls actually work.
Course Availability:
Contact us for schedule dates and times.
View the course calendar and browse for our schedule.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

