Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

An organization is deploying an IPv6-only network segment for its IoT devices. They need to ensure that these devices can securely communicate with internal IPv4-only servers for data collection, without requiring a full dual-stack implementation on the IoT devices or the servers. Which IPv6 transition mechanism is most appropriate for this specific scenario?

  1. ANAT64 with DNS64
  2. BISATAP tunneling
  3. CDual-stack
  4. D6to4 tunneling
Show answer & explanation

Correct answer: A. NAT64 with DNS64

NAT64 with DNS64 is designed for IPv6-only clients to communicate with IPv4-only servers. DNS64 translates IPv4 addresses into synthetic IPv6 addresses, and NAT64 translates the IPv6 packet headers to IPv4 as they cross between the IPv6 and IPv4 networks, without requiring dual-stack on either endpoint.

Why the other options are wrong

  • B. ISATAP is for connecting IPv6 hosts over an IPv4 infrastructure within a single site, primarily for IPv6 adoption, not for IPv6-only to IPv4-only server communication.
  • C. Dual-stack requires both IPv4 and IPv6 on endpoints, which is explicitly not desired for the IoT devices.
  • D. 6to4 is for connecting isolated IPv6 networks over an IPv4 backbone, not for IPv6-only clients to IPv4-only servers.

NAT64 and DNS64

A combination of IPv6 transition mechanisms that allows IPv6-only clients to communicate with IPv4-only servers. DNS64 synthesizes AAAA records for IPv4-only destinations, and NAT64 translates IPv6 packets to IPv4 packets at a gateway.

  • Enables IPv6-only clients to reach IPv4-only servers.
  • DNS64 translates IPv4 addresses to IPv6-mapped IPv6 addresses.
  • NAT64 performs the actual header translation at a gateway.
  • No dual-stack required on client or server.

Memory trick: NAT64 and DNS64 are the interpreters between IPv6-only and IPv4-only worlds.

More Visibility and Enforcement questions