AD-SUB-05 - IPv6 catch-all subnets count should be retrievable
Overviewโ
Overly broad IPv6 subnets can cause similar issues to IPv4 catch-all subnets:
- Authentication inefficiency: Clients may authenticate to distant DCs
- Suboptimal routing: Site boundaries don't reflect actual topology
- Management complexity: Difficult to track client locations
- Security concerns: Reduced granularity in access controls
IPv6 /48 prefixes or larger are considered catch-all ranges.
Security Recommendationโ
- Use appropriately-sized IPv6 subnets (typically /64 for client networks)
- Align IPv6 subnet boundaries with physical locations
- Document IPv6 subnet allocation scheme
- Review IPv6 subnet definitions regularly
How the Test Worksโ
This test identifies IPv6 subnets with overly broad prefixes (/48 or smaller).
Related Testsโ
Test-MtAdSubnetIpv6Count- Counts IPv6 subnetsTest-MtAdSubnetCatchAllCount- Identifies IPv4 catch-all subnetsTest-MtAdSubnetTotalCount- Counts total subnets
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SUB-05 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Site |
| PowerShell test | Test-MtAdSubnetIpv6CatchAllCount |
| Tags | AD, AD-SUB-05, AD.Site |
Sourceโ
- Pester test:
tests/ad/site/Test-MtAdSubnetIpv6CatchAllCount.Tests.ps1 - PowerShell source:
powershell/public/ad/site/Test-MtAdSubnetIpv6CatchAllCount.ps1

