Configuring Nd Detection; Displaying And Maintaining Nd Detection; Nd Detection Configuration Example - HP A5830 Series Configuration Manual

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

The ND snooping table is created automatically by the ND snooping module. For more information, see
Layer 3—IP Services Configuration Guide.

Configuring ND detection

ND detection performs source check by using the binding tables of IP source guard, DHCPv6 snooping,
and ND snooping. To prevent an ND-untrusted port from discarding legal ND packets in an ND
detection-enabled VLAN, make sure that at least one of these functions is available.
When you create an IPv6 static binding with IP source guard for ND detection in a VLAN, specify the
VLAN ID for the binding. Otherwise, no ND packets in the VLAN can match the binding.
The ND detection function does not check ND packets containing link local addresses.
To enable ND detection for a VLAN and specify a trusted port:
To do...
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ND Detection.
Quit system view.
4.
5.
Enter Layer 2 Ethernet interface
view or Layer 2 aggregate
interface view.
6.
Configure the port as an ND-
trusted port.

Displaying and maintaining ND detection

To do...
Display the ND detection
configuration
Display the statistics of
discarded packets when the ND
detection checks the user
legality
Clear the statistics by ND
detection

ND detection configuration example

Network requirements
As shown in
has the IPv6 address 10::5 and MAC address 0001-0203-0405. Host B has the IPv6 address 10::6
and MAC address 0001-0203-0607.
Use the command...
display ipv6 nd detection [ | { begin | exclude
| include } regular-expression ]
display ipv6 nd detection statistics [ interface
interface-type interface-number ] [ | { begin |
exclude | include } regular-expression ]
reset ipv6 nd detection statistics [ interface
interface-type interface-number ]
Figure
79, Host A and Host B connect to Switch A, the gateway, through Switch B. Host A
Use the command...
system-view
vlan vlan-id
ipv6 nd detection enable
quit
interface interface-type interface-
number
ipv6 nd detection trust
241
Remarks
––
––
Required.
Disabled by default.
––
––
Optional.
A port does not trust sources
of ND packets by default.
Remarks
Available in any view
Available in any view
Available in user view

Advertisement

Table of Contents
loading

Table of Contents