Skip to main content
Version: 2.2.1-preview

AD-SUB-04 - IPv6 subnets count should be retrievable

Overviewโ€‹

IPv6 subnet configuration is important for:

  • Future-proofing: IPv6 adoption continues to grow
  • Dual-stack environments: Supporting both IPv4 and IPv6 clients
  • Compliance: Meeting IPv6 readiness requirements
  • Modern networks: Many modern networks are IPv6-first

Understanding IPv6 subnet deployment helps assess the organization's IPv6 readiness.

Security Recommendationโ€‹

  • Define IPv6 subnets for all locations where IPv6 is deployed
  • Ensure IPv6 subnets mirror IPv4 site topology
  • Document IPv6 addressing scheme
  • Plan for IPv6-only client support

How the Test Worksโ€‹

This test counts subnets that use IPv6 address format (containing colons).

  • Test-MtAdSubnetIpv6CatchAllCount - Identifies overly broad IPv6 subnets
  • Test-MtAdSubnetTotalCount - Counts total subnets
  • Test-MtAdSubnetSiteAssociationCount - Counts sites with subnets

Test Metadataโ€‹

FieldValue
Test IDAD-SUB-04
SeverityInfo
SuiteActive Directory
CategoryAD.Site
PowerShell testTest-MtAdSubnetIpv6Count
TagsAD, AD-SUB-04, AD.Site

Sourceโ€‹

  • Pester test: tests/ad/site/Test-MtAdSubnetIpv6Count.Tests.ps1
  • PowerShell source: powershell/public/ad/site/Test-MtAdSubnetIpv6Count.ps1