mediumMultiple Choice
Troubleshoot IPv6 Source Guard Dropping OSPFv3 Due to Missing Link-Local Binding
A network engineer is troubleshooting an issue where IPv6 traffic is being forwarded incorrectly on a switch. The switch is configured with IPv6 Source Guard on access ports. A legitimate host on port Fa0/1 with IPv6 address 2001:db8:1::10 is unable to send traffic to the default gateway. The engineer checks the IPv6 binding table and sees that the host's entry is missing. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the dependency of IPv6 Source Guard on ND snooping, and the trap here is that candidates assume IPv6 Source Guard works independently or that static addresses are automatically learned, when in fact the binding table must be populated either dynamically via ND snooping or manually.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The host is using a static IPv6 address, and ND snooping is not enabled on the VLAN, so the binding was never learned.
IPv6 Source Guard relies on the IPv6 binding table, which is populated by IPv6 Neighbor Discovery (ND) snooping. If the host uses a static IPv6 address and ND snooping is not enabled on the VLAN, the switch never learns the binding, so IPv6 Source Guard drops the traffic as unauthorized. Enabling ND snooping allows the switch to inspect Neighbor Solicitation and Advertisement messages to build the binding table dynamically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The host is using a static IPv6 address, and ND snooping is not enabled on the VLAN, so the binding was never learned.
Why this is correct
IPv6 Source Guard validates traffic by consulting the neighbor discovery (ND) snooping binding table, which records IPv6-to-MAC mappings learned from Neighbor Advertisements and Solicitations. If ND snooping is disabled on the VLAN, no binding entries are ever populated, even for hosts using statically configured IPv6 addresses. Because the switch has no record of this host's source IPv6 address, IPv6 Source Guard classifies the traffic as invalid and silently drops it, preventing forwarding despite the host being correctly configured.
- ✗
The host's MAC address is not in the MAC address table for VLAN 1.
Why it's wrong here
The Layer 2 MAC address table governs switching decisions, such as where to forward Ethernet frames within a VLAN. IPv6 Source Guard operates at Layer 3, filtering packets based on the IPv6 source address against the IPv6 binding table maintained by ND snooping. Even if the host's MAC address is present in the MAC address table, the switch will still drop the IPv6 traffic when that source IPv6 address lacks a binding entry; the MAC table's state is irrelevant to the IPv6 Source Guard check.
- ✗
The switch is running IPv6 First Hop Security in monitor mode, which logs violations but does not drop traffic.
Why it's wrong here
When IPv6 First Hop Security features like IPv6 Source Guard run in monitor mode, they are configured to detect and log security violations without enforcing any drop action. The described symptom is that the host's traffic is being dropped, which indicates the switch is actively enforcing policy rather than merely monitoring. In monitor mode, the traffic would be forwarded normally while generating a log or notification, so this option contradicts the observed behavior and cannot explain the failure.
- ✗
The default gateway router is not sending Router Advertisements, so the host cannot form a default route.
Why it's wrong here
Router Advertisements (RAs) are used by hosts for IPv6 stateless address autoconfiguration and default route derivation; the absence of RAs would prevent the host from building a default gateway route. However, the problem statement focuses on the switch dropping the host's traffic, which is an IPv6 Source Guard action based on the binding table. A missing default route would cause the host to consider destinations unreachable or send packets to the wrong next hop, but it would not cause the switch itself to drop the packets at Layer 3.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.