Ipv6 Nd Inspection Drop-Unsecure - Cisco Sx350 Cli Manual

Hide thumbs Also See for Sx350:
Table of Contents

Advertisement

IPv6 First Hop Security
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
switchxxxxxx(config)#
switchxxxxxx(config-if)#
switchxxxxxx(config-if)#

29.26 ipv6 nd inspection drop-unsecure

To globally enable dropping messages with no CGA and RSA Signature options,
use the ipv6 nd inspection drop-unsecure command in Global Configuration
mode. To disable this function, use the no form of this command.
Syntax
ipv6 nd inspection drop-unsecure
no ipv6 nd inspection drop-unsecure
Parameters
N/A
Default Configuration
All messages are bridged.
Command Mode
Global Configuration mode
User Guidelines
This command drops NDP messages if they do not contain CGA and RSA
Signature options.
If this command is not configured, then the sec-level minimum command does not
have an effect.
If this command is configured, then only the sec-level minimum command has an
effect and all other configured ND Inspection policy commands are ignored.
Example
The following example enables the switch to drop messages with no or invalid
options or an invalid signature:
interface vlan 100
ipv6 nd inspection attach-policy policy1
exit
29
642

Advertisement

Table of Contents
loading

Table of Contents