Skip to main content
Version: 2.2.1-preview

AD-SUB-05 - IPv6 catch-all subnets count should be retrievable

Overviewโ€‹

Overly broad IPv6 subnets can cause similar issues to IPv4 catch-all subnets:

  • Authentication inefficiency: Clients may authenticate to distant DCs
  • Suboptimal routing: Site boundaries don't reflect actual topology
  • Management complexity: Difficult to track client locations
  • Security concerns: Reduced granularity in access controls

IPv6 /48 prefixes or larger are considered catch-all ranges.

Security Recommendationโ€‹

  • Use appropriately-sized IPv6 subnets (typically /64 for client networks)
  • Align IPv6 subnet boundaries with physical locations
  • Document IPv6 subnet allocation scheme
  • Review IPv6 subnet definitions regularly

How the Test Worksโ€‹

This test identifies IPv6 subnets with overly broad prefixes (/48 or smaller).

  • Test-MtAdSubnetIpv6Count - Counts IPv6 subnets
  • Test-MtAdSubnetCatchAllCount - Identifies IPv4 catch-all subnets
  • Test-MtAdSubnetTotalCount - Counts total subnets

Test Metadataโ€‹

FieldValue
Test IDAD-SUB-05
SeverityInfo
SuiteActive Directory
CategoryAD.Site
PowerShell testTest-MtAdSubnetIpv6CatchAllCount
TagsAD, AD-SUB-05, AD.Site

Sourceโ€‹

  • Pester test: tests/ad/site/Test-MtAdSubnetIpv6CatchAllCount.Tests.ps1
  • PowerShell source: powershell/public/ad/site/Test-MtAdSubnetIpv6CatchAllCount.ps1