Setting The Maximum Number Of Ipv6 Source Guard Entries; Displaying And Maintaining Ip Source Guard - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

NOTE:
To implement dynamic IPv6 source guard, make sure that DHCPv6 snooping or ND snooping is
configured and works normally. For DHCPv6 and ND snooping configuration information, see the
3—IP Services Configuration Guide
If you configure dynamic IPv6 source guard on a port for multiple times, the last configuration will
overwrite the previous configuration on the port.
If you configure both ND snooping and DHCPv6 snooping on the device, IP source guard generates IP
source guard entries based on the DHCPv6 snooping entries, which are usually generated first, to filter
packets on a port.

Setting the maximum number of IPv6 source guard entries

The maximum number of IPv6 source guard entries is used to limit the total number of static and dynamic
IPv6 source guard entries on a port. When the number of IPv6 binding entries on a port reaches the
maximum, the port does not allow new IPv6 binding entries any more.
Follow these steps to configure the maximum number of IPv6 binding entries allowed on a port:
To do...
Enter system view
Enter Layer 2 Ethernet interface
view
Configure the maximum number of
IPv6 binding entries allowed on the
port
NOTE:
If the maximum number of IPv6 binding entries to be configured is smaller than the number of existing IPv6
binding entries on the port, the maximum number can be configured successfully and the existing entries
will be not be affected. New IPv6 binding entries, however, cannot be added more unless the number of
IPv6 binding entries on the port drops below the configured maximum.

Displaying and maintaining IP source guard

For IPv4:
To do...
Display static IPv4 source guard
entries
Display IPv4 source guard entries
For IPv6:
.
Use the command...
system-view
interface interface-type
interface-number
ip check source ipv6 max-entries
number
Use the command...
display user-bind [ interface interface-type
interface-number | ip-address ip-address |
mac-address mac-address ] [ | { begin |
exclude | include } regular-expression ]
display ip check source [ interface
interface-type interface-number |
ip-address ip-address | mac-address
mac-address ] [ slot slot-number ] [ | { begin
| exclude | include } regular-expression ]
295
Remarks
Optional
256 by default.
Remarks
Available in any view
Available in any view
Layer

Advertisement

Table of Contents
loading

Table of Contents