Valid

GB/T 46240.2-2025Security requirements and testing methods of IPv6 network equipment — Part 2: Switch (English PDF)

IPv6网络设备安全技术要求和测试方法 第2部分:交换机

Open the GB/T 46240.2-2025 preview as PDF

Preview — first pages of GB/T 46240.2-2025 (full document: 35 pages)

This is a limited preview

Buy now to download the full PDF (35 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

August 29, 2025

Implementation date

December 1, 2025

Scope

GB/T 46240.2-2025 is the English-translated version of IPv6网络设备安全技术要求和测试方法 第2部分:交换机.

GB/T 46240.2-2025 is the Chinese national standard covering securing an IPv6 switch — the port security and the first-hop protections against rogue router advertisements and DHCPv6 servers, the neighbour discovery inspection, the source guard, the management access, and the tests that prove each. At 21,500 words. Part 2 of the series, with the router requirements in Part 1. First edition, in force from 1 December 2025. Issued on 29 August 2025, it has been in force since 1 December 2025.

Document preview — GB/T 46240.2-2025

National Standard of the People's Republic of China

ICS
33.040.40
Classification
M 32

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • PrefaceV
  • IntroductionVI
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations1
  • 5 General Principles2
  • 6 Safety Technical Requirements3
  • 6.1 Data Plane Security3
  • 6.1.1 Identification and Authentication3
  • 6.1.2 Trusted Channel3
  • 6.1.3 System Access3
  • 6.1.4 Resource Allocation3
  • 6.1.4.1 Ability to resist large-volume attacks3
  • 6.1.4.2 Anti-deformation package capability4
  • 6.1.4.3 ND Illegal Packet Attack Protection4
  • 6.1.4.4 IPv6 address spoofing protection4
  • 6.1.4.5 Multicast Packet Suppression4
  • 6.1.5 Security Audit4
  • 6.1.5.1 Attack Source Tracing Function4
  • 6.1.5.2 Sampling function4
  • 6.1.6 System Function Protection5
  • 6.1.7 Security Management5
  • 6.2 Control Plane Security5
  • 6.2.1 Identification and identification5
  • 6.2.1.1 Routing Authentication5
  • 6.2.1.2 ND message authentication function5
  • 6.2.1.3 Intelligent Lossless Storage Network Authentication5
  • 6.2.1.4 Cross-device link aggregation authentication5
  • 6.2.1.5 OpenFlow Authentication5
  • 6.2.2 Trusted Channel5
  • 6.2.3 System Access6
  • 6.2.4 Resource Allocation6
  • 6.2.4.1 MAC Address Learning Limitation6
  • 6.2.4.2 Disabling ICMPv66
  • 6.2.4.3 Disable the Hop-by-Hop option6
  • 6.2.5 Security Audit6
  • 6.2.6 System Function Protection6
  • 6.2.7 Security Management6
  • 6.3 Management Plane Security6
  • 6.3.1 Identification and Authentication6
  • 6.3.2 Trusted Channel6
  • 6.3.3 System Access7
  • 6.3.3.1 Access Control Security7
  • 6.3.3.2 Serial Port Access7
  • 6.3.3.3 SSH Access7
  • 6.3.3.4 SNMP Access7
  • 6.3.3.5 Web Access7
  • 6.3.4 Resource Allocation7
  • 6.3.5 Security Audit8
  • 6.3.6 System Function Protection8
  • 6.3.7 Security Management8
  • 6.3.7.1 Hierarchical and decentralized management8
  • 6.3.7.2 Insecure Configuration Check8
  • 6.3.7.3 Digital Certificate Management8
  • 6.3.7.4 Password Requirements8
  • 7 Test Methods8
  • 7.1 Test Environment8
  • 7.2 Data Plane Security Testing10
  • 7.2.1 Identification and identification10
  • 7.2.1.1 802.1X Access Authentication Function10
  • 7.2.1.2 MAC access authentication function11
  • 7.2.1.3 MAC Address Drift Detection Function11
  • 7.2.2 Trusted Channel11
  • 7.2.3 System Access11
  • 7.2.4 Resource Allocation12
  • 7.2.4.1 Ability to resist large-volume attacks12
  • 7.2.4.2 Anti-deformation package capability13
  • 7.2.4.3 ND Illegal Packet Attack Protection15
  • 7.2.4.4 IPv6 address spoofing protection15
  • 7.2.4.5 Multicast Packet Suppression16
  • 7.2.5 Security Audit16
  • 7.2.5.1 Attack Source Tracing Function16
  • 7.2.5.2 Sampling function16
  • 7.2.6 System Function Protection16
  • 7.2.7 Security Management17
  • 7.3 Control Plane Security Testing17
  • 7.3.1 Identification and identification17
  • 7.3.1.1 Routing Authentication17
  • 7.3.1.2 ND message authentication function18
  • 7.3.1.3 Intelligent Lossless Storage Network Certification19
  • 7.3.1.4 Cross-device link aggregation authentication20
  • 7.3.1.5 OpenFlow Authentication20
  • 7.3.2 Trusted Channel20
  • 7.3.2.1 RIPng supports IPsec function20
  • 7.3.2.2 OSPFv3 Supports IPsec21
  • 7.3.2.3 BGP4 supports TLS21
  • 7.3.3 System Access21
  • 7.3.3.1 BGP4 Inbound Route Filtering21
  • 7.3.3.2 BGP4 Outbound Route Filtering21
  • 7.3.3.3 Route filtering based on BGP4 attributes22
  • 7.3.3.4 Route Filtering in Route Redistribution22
  • 7.3.4 Resource Allocation22
  • 7.3.4.1 MAC Address Learning Limit22
  • 7.3.4.2 Disabling ICMPv6 Function23
  • 7.3.4.3 Disabling the Hop-by-Hop Option23
  • 7.3.5 Security Audit23
  • 7.3.6 System Function Protection23
  • 7.3.7 Security Management24
  • 7.4 Management Plane Security Testing24
  • 7.4.1 Identification and identification24
  • 7.4.2 Trusted Channel24
  • 7.4.2.1 SSH24
  • 7.4.2.2 TLS24
  • 7.4.3 System Access25
  • 7.4.3.1 Access Control Security25
  • 7.4.3.2 Serial Port Access25
  • 7.4.3.3 SSH Access25
  • 7.4.3.4 SNMP Access26
  • 7.4.3.5 Web Access26
  • 7.4.4 Resource Allocation26
  • 7.4.4.1 Management Plane Protocol Prevention of Abnormal Message Attacks26
  • 7.4.4.2 Management Plane Protocol Prevents Denial of Service Attacks27
  • 7.4.5 Security Audit27
  • 7.4.6 System Function Protection27
  • 7.4.6.1 Encrypted storage of sensitive data27
  • 7.4.6.2 Secure Boot Function27
  • 7.4.6.3 Pre-installed software startup and update security28
  • 7.4.7 Security Management28
  • 7.4.7.1 Hierarchical and decentralized management28
  • 7.4.7.2 Insecure Configuration Check28
  • 7.4.7.3 Digital Certificate Management28
  • Reference29

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.

This document is Part 2 of GB/T 46240 "Technical Requirements and Test Methods for IPv6 Network Equipment Security".

The following parts were published.

— Part 1: Routers;

— Part 2: Switches.

Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document is proposed by the Ministry of Industry and Information Technology of the People's Republic of China.

This document is under the jurisdiction of the National Communications Standardization Technical Committee (SAC/TC485).

This document was drafted by: China Academy of Information and Communications Technology, Huawei Technologies Co., Ltd., and the National Computer Network Emergency Response Technical Processing Coordination Center.

Center, China National Petroleum and Natural Gas Pipeline Network Corporation, China Telecom Consulting and Design Institute Co., Ltd., ZTE Corporation, State Industry Information Security Development Research Center, China Welfare Institute International Peace Maternal and Child Health Hospital, Hillstone Network Technology Co., Ltd., Harbin Howard College.

The main drafters of this document are: Ge Pei, Xia Liqiang, Liu Shu, Hu Junli, Wang Wenlei, Qu Jiewu, Wang Li, Li Changlian, Wang Dongbo, Zhou Jihua, Liu Zihe, Chen Changjie, Xu Jun, and Wu Di.

Introduction

According to the Notice on Accelerating the Scale Deployment and Application of Internet Protocol Version 6 (IPv6), in order to speed up the solution of network equipment In order to address the security deficiencies of IPv6 and promote the standardization of IPv6 large-scale deployment and application innovations, China has formulated a series of IPv6 application standards.

Among them, GB/T 46240 "IPv6 Network Equipment Security Technical Requirements and Test Methods" is to standardize and guide the smooth deployment of IPv6 in China.

The standards formulated to promote the development of the industry are planned to consist of two parts.

— Part 1: Routers. The purpose is to propose and standardize the development and application of IPv6 security for routers.

— Part 2: Switches. The purpose is to propose and standardize the development and application of IPv6 security on switches.

IPv6 network equipment security technical requirements and testing methods Part 2: Switches

1 Scope

This document specifies the security architecture of switches supporting IPv6 capabilities, as well as security technologies for the data plane, control plane, and management plane.

requirements and describes the corresponding test methods.

This document is applicable to the design, development, and testing of switch devices that support IPv6 capabilities.

2 Normative references

GB/T 25069

GB/T 41267-2022

3 Terms and Definitions

The terms and definitions defined in GB/T 25069 and the following apply to this document.

3.1 switch

A device that uses an internal switching mechanism to provide connectivity between networked devices.

NOTE. The switching mechanisms in a switch are typically implemented at Layer 2 or Layer 3 of the Open Systems Interconnection (OSI) reference model.

[Source. GB/T 41267-2022, 3.1]

4 Abbreviations

The following abbreviations apply to this document.

ACL. Access Control List (AccessControlList) CLI. Command-Line Interface DUT. Device Under Test

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 35 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 46240.2

EditionTitleRevisionStatus
GB/T 46240.2-2025Security requirements and testing methods of IPv6 network equipment - Part 2: Switchcurrent editionCurrent

This page sells the current edition, GB/T 46240.2-2025. Earlier editions are listed for reference only.

How to Buy GB/T 46240.2-2025

  1. 1Add to cart. Click the "Buy GB/T 46240.2-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
35 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 46240.2-2025

$635.00

$540.00for partners