Summary
- On 2 September 2026, the IESG opened Last Call on revision 08 of the IPv6 Neighbor Discovery YANG model, with comments due on 16 September. It is a Proposed Standard candidate, not an approved RFC or deployment record.
- The proposed
retrans-timeris one writable interface value used by address resolution, Neighbor Unreachability Detection and Duplicate Address Detection. Aggregate counters become useful evidence only when joined to configuration and discontinuity epochs, interface identity and observed effect.
The easiest management error to audit is a wrong value in one obvious box. The harder error is a correct value whose scope is wider than the change ticket suggests. Revision 08 of the proposed ietf-ipv6-nd model creates exactly that leadership problem. It gives operators a common vocabulary for IPv6 Neighbor Discovery, but common vocabulary also makes a shared blast radius machine-readable.
The draft augments the IPv6 portion of the interface model. It covers address resolution, Redirect, proxy Neighbor Advertisement, Neighbor Unreachability Detection, Duplicate Address Detection and Enhanced DAD. It does not try to absorb every first-hop function. Router and Prefix Discovery remain in the routing model; static neighbor entries and Stateless Address Autoconfiguration remain in the IP model; low-power ND extensions remain outside this module. That restraint matters. A management surface should state both what it can change and what another model still owns.
The consequential leaf is retrans-timer. It is measured in milliseconds, defaults to 1000 and accepts values from one upward. The same value controls retransmission of Neighbor Solicitations used for three different purposes: learning a link-layer address, probing whether a neighbor remains reachable and testing whether a tentative address is already in use.
Those purposes fail differently. Slow address resolution delays first contact. Slow NUD postpones active evidence after reachability has become doubtful. Slow DAD extends the interval before a tentative address can be used. An aggressive value can produce unnecessary signalling across all three. A management transaction can therefore succeed exactly while a service degrades for a reason that the transaction log does not name.
The model offers other sensitive choices. reachable-time decides how long a positive reachability confirmation remains current before a dynamic neighbor becomes STALE. The draft warns that an excessively large value can prolong the effect of spoofed cache state, while an excessively small one can provoke frequent NUD. This is not merely tuning. It is a decision about how quickly yesterday's evidence loses authority.
The redirect and proxy-na booleans default to false. Enabling Redirect permits the node to advise a host of a different first hop. Enabling proxy Neighbor Advertisement permits a router to answer for an IPv6 destination that is not its own, using the router's link-layer address. Both features can be useful. Both also expand who can influence packet direction, which is why the security section treats unauthorized writes as possible paths to misdirection, spoofing and denial of service.
Enhanced DAD adds another decision surface. Its enable switch and the conditional auto-resolve switch both default to false. When automation is enabled and a duplicate is detected, a trusted router may log an event, drop the ND message and block the host from which the duplicate solicitation or advertisement arrived. The word “duplicate” is an observation; the decision to block is an enforcement act. Loopback, fault, conflict and hostile behavior must not be collapsed into one identity claim.
The base IP model also matters. Its dup-addr-detect-transmits value can be set to zero, disabling DAD. A screen that displays Enhanced DAD as enabled while omitting the inherited base leaf can show two individually valid fragments and still misrepresent the effective behavior. Schema composition is not automatically operator comprehension.
Revision 08 pairs these writes with a large read-only statistics tree. It counts incoming, outgoing and dropped Neighbor Solicitations, Neighbor Advertisements, Router Solicitations, Router Advertisements and Redirects. It separates unicast and multicast and exposes drop reasons such as invalid code, hop limit, length, option, checksum or fragmentation. It also counts NUD solicitations and selected advertisement flags.
That is valuable visibility, but it is not a causal ledger. The imported counter64 type has no defined initial value. Its own specification says a single reading generally has no information content. A counter can wrap, restart with the management system or suffer another discontinuity. If discontinuities can occur elsewhere, a corresponding node should identify the last one. The draft's ND statistics tree does not itself place such an epoch beside the counters.
This absence does not prove that a device exposes no boot time or discontinuity elsewhere. It means the join is outside the proposed subtree. A dashboard that subtracts two values without checking restart context can manufacture a rate. A dashboard that compares a rate with a timer change without binding both to the same interface and configuration generation can manufacture a cause.
The dynamic-neighbor age leaf is similarly narrow. It reports seconds since the last reachability confirmation and is ignored for a static entry. A small age is evidence of recent confirmation under the protocol's rules. It does not authenticate a machine, establish ownership, guarantee present delivery or show that an application succeeded.
The IESG Last Call is open until 16 September. The Datatracker also reports zero errors and zero warnings from YANG validators. Both are real receipts at their own layer. Neither says that revision 08 will be approved unchanged, that a vendor implements it, that a datastore applies it correctly or that a packet will follow the intended path.
Sources
- IETF Datatracker document record
- IETF Datatracker history
- IETF Datatracker references
- Heng Lu, Minimum Initial Specification
- Heng Lu, Reality Layers
- Heng Lu, Running-Code Primacy
- IESG Last Call announcement
- Draft revision 08
- RFC 4861
- RFC 4862
- RFC 6241
- RFC 7527
- RFC 7950
- RFC 8040
- RFC 8341
- RFC 8342
- RFC 8343
- RFC 8344
- RFC 8349
- RFC 9911
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
