Ipv6 Nd Inspection Validate Source-Mac - Cisco 300 Series Cli Manual

Stackable managed switches
Hide thumbs Also See for 300 Series:
Table of Contents

Advertisement

25
IPv6 First Hop Security
Example
The following example enables the switch to specify 2 as the minimum CGA
security level:
switchxxxxxx(config)#
ipv6 nd inspection sec-level minimum 2

25.29 ipv6 nd inspection validate source-mac

To globally enable checking source MAC address against the link-layer address in
the source/target link-layer option, use the ipv6 nd inspection validate source-mac
command in Global Configuration mode. To disable this function, use the no form
of this command.
Syntax
ipv6 nd inspection validate source-mac
no ipv6 nd inspection validate source-mac
Parameters
N/A
Default Configuration
This command is disabled by default.
Command Mode
Global Configuration mode
User Guidelines
When the switch receives an NDP message, which contains a link-layer address in
the source/target link layer option, the source MAC address is checked against
the link-layer address. Use this command to drop the packet if the link-layer
address and the MAC addresses are different from each other.
523
OL-32830-01 Command Line Interface Reference Guide

Advertisement

Table of Contents
loading

Table of Contents