Skip to main content

What do think of SLDP. Layer-2 discovery for IPv4/IPv6

0
Medium
Published: 09/17/2026 (09/17/2026, 09:11:34 UTC)
Source: Reddit BlueTeam

Description

SLDP (Simple Layer-2 Discovery Protocol) is a lightweight, stateless Layer-2 bootstrapping protocol designed to automate discovery between IPv4-only and IPv6-only devices on a common broadcast domain. It operates directly over Ethernet frames without requiring IP stack initialization and is intended as a commissioning tool rather than a runtime protocol. SLDP uses a dedicated EtherType and a two-step handshake to establish MAC-to-IP mappings, facilitating integration in mixed IPv4/IPv6 environments such as industrial IoT and legacy networks. It is not a replacement for ARP, NDP, or LLDP and runs only on demand during device commissioning. The protocol includes a security blueprint (CLL Trust Oracle) to protect against address spoofing during discovery. No known exploits or vulnerabilities have been reported, and no patch or remediation is applicable as this is a newly proposed protocol.

Reddit Discussion

r/AskNetsec·posted by u/LY70N
00

I built SLDP (Simple Layer-2 Discovery Protocol) to solve the manual MAC-to-IP mapping nightmare when integrating IPv6-only devices into legacy IPv4 networks (industrial IoT, substations, etc.).

How it works:

· Operates directly over Ethernet frames (EtherType 0x88B5).
· Requires zero IP stack initialization (no IP, DHCP, DNS, or sockets).
· Stateless broadcast/unicast handshake.
· Runs on-demand during commissioning, then goes silent in production.

What it is NOT:
It's not a replacement for ARP/NDP/LLDP, and not a runtime protocol. Just a targeted bootstrapping tool.

I've written a C implementation for Linux, a security blueprint (CLL Trust Oracle), and included a Wireshark dissector in the repo so you can easily inspect the frames.

The Ask: I'm looking for feedback from network engineers. Does this solve a real problem for you? Are there glaring architectural flaws?

Repo: https://github.com/cyberghost-2/Simple-L2-Discovery-protocol-SLDP-

Bug reports and critiques are very welcome. Thanks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 14:17:11 UTC

Technical Analysis

SLDP is a specialized Layer-2 discovery protocol designed to bridge IPv4-only and IPv6-only devices by performing an on-demand handshake over Ethernet frames (EtherType 0x88B5) without requiring IP stack initialization. It addresses operational challenges in hybrid network environments by automating MAC-to-IP mapping during commissioning phases. The protocol exchanges a broadcast DISCOVERY_REQ followed by a unicast DISCOVERY_RESP containing session and address information encoded uniformly. SLDP is explicitly not a runtime protocol and does not replace existing address resolution protocols. It includes a security design based on the CLL Trust Oracle to mitigate spoofing risks during discovery. The implementation is open source with a Wireshark dissector for traffic analysis. No vulnerabilities or active exploits are reported.

Potential Impact

SLDP itself is a protocol proposal and implementation intended to simplify network commissioning in mixed IPv4/IPv6 environments. There is no indication of inherent vulnerabilities or exploitation in the provided information. The impact is primarily operational, potentially reducing manual configuration errors and improving integration efficiency. No security incidents or exploit code are known. The security blueprint aims to mitigate spoofing risks during commissioning.

Defensive Guidance

No remediation or patch is applicable as SLDP is a newly introduced protocol and tool without reported vulnerabilities. Users should review the security blueprint (CLL Trust Oracle) included in the implementation to ensure appropriate protections against spoofing during commissioning. Since SLDP is designed to run only on demand and not in production, limiting its use to commissioning phases reduces exposure. Network engineers should evaluate the protocol carefully before deployment and monitor for any future advisories.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aabf65f55bf5e2cf57b2f44

Added to database: 09/17/2026, 14:17:03 UTC

Last enriched: 09/17/2026, 14:17:11 UTC

Last updated: 09/18/2026, 03:01:41 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses