Ipv6 Nd Raguard - Cisco 300 Series Cli Manual

Stackable managed switches
Hide thumbs Also See for 300 Series:
Table of Contents

Advertisement

IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
Example
The following example enables the switch to drop an NDP message whose
link-layer address in the source/target link-layer option does not match the MAC
address:
switchxxxxxx(config)#

25.30 ipv6 nd raguard

To globally enable the Router Advertisements (RA) guard feature on a VLAN, use
the ipv6 nd raguard command in VLAN Configuration mode. To return to the
default, use the no form of this command.
Syntax
ipv6 nd raguard
no ipv6 nd raguard
Parameters
N/A
Default Configuration
RA Guard on a VLAN is disabled.
Command Mode
Interface (VLAN) Configuration mode
User Guidelines
Use the ipv6 nd raguard command, to enable IPv6 RA Guard on a VLAN.
RA Guard discards RA, CPA, and ICMP Redirect messages received on ports that
are not configured as router (see the device-role command).
RA Guard validates received RA messages based on an RA Guard policy
attached to the source port.
RA Guard is performed before ND inspection.
ipv6 nd inspection validate source-mac
25
524

Advertisement

Table of Contents
loading

Table of Contents