The IPv6 Secure Neighbor Discovery (SEND) function authenticates the communicating network devices, protecting network devices against pseudo attacks.
On the network shown in Figure 1, the FW functions as the gateway for hosts. After SEND is configured, the network device applies for a local certificate carrying the device's identity information, public key, a digital signature of the authentication center from the PKI authentication center. In stateless autoconfiguration environment, when a host requests the device's local certificate, the device returns its local certificate. The host authenticates the certificate, and accepts the device as gateway if the authentication is successful.