Static Ipv6 Source Guard Configuration Example; Dynamic Ipv6 Source Guard Using Dhcpv6 Snooping Configuration Example - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

192.168.0.1
The output shows that a dynamic IPv4 source guard binding entry is generated based on a DHCP relay
entry.

Static IPv6 source guard configuration example

Network requirements
As shown in
1/0/1 of the device to allow only IPv6 packets from the host to pass.
Figure 108 Network diagram
Configuration procedure
# Enable IPv6 source guard on Ten-GigabitEthernet 1/0/1.
<Switch> system-view
[Switch] interface ten-gigabitethernet 1/0/1
[Switch-Ten-GigabitEthernet1/0/1] ipv6 verify source ip-address mac-address
# On Ten-GigabitEthernet 1/0/1, configure a static IPv6 source guard binding entry for the host.
[Switch-Ten-GigabitEthernet1/0/1] ipv6 source binding ip-address 2001::1 mac-address
0001-0202-0202
[Switch-Ten-GigabitEthernet1/0/1] quit
# Display static IPv6 source guard binding entries on the device. The output shows that a static IPv6
source guard binding entry is configured successfully.
[Switch] display ipv6 source binding static
Total entries found: 1
IPv6 Address
2001::1
Dynamic IPv6 source guard using DHCPv6 snooping
configuration example
Network requirements
As shown in
Enable DHCPv6 snooping on the device to record the IPv6 address and the MAC address of the
host in a DHCPv6 snooping entry.
Enable dynamic IPv6 source guard on Ten-GigabitEthernet 1/0/1 to filter received packets based
on DHCPv6 snooping entries, allowing only packets from a client that obtains an IP address from
the DHCPv6 server to pass.
0001-0203-0406 Vlan100
Figure
108, configure a static IPv6 source guard binding entry for Ten-GigabitEthernet
MAC Address
0001-0202-0202 XGE1/0/1
Figure
109:
Interface
324
100
DHCP relay
VLAN Type
N/A
Static

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents