Displaying And Maintaining Ra Guard; Ra Guard Configuration Example - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

more information about the information center, see Network Management and Monitoring
Configuration Guide.
To enable the RA guard logging feature:
Step
1.
Enter system view.
2.
Enable the RA guard logging
feature.

Displaying and maintaining RA guard

Execute display commands in any view and reset commands in user view.
Task
Display the RA guard policy configuration.
Display RA guard statistics.
Clear RA guard statistics.

RA guard configuration example

Network requirements
As shown in
Device B are in VLAN 10.
Configure RA guard on Device B to filter forged and unwanted RA messages.
Configure an RA policy in VLAN 10 for GigabitEthernet 1/0/2 to filter all RA messages received
from the unknown device.
Specify host as the role of the host. All RA messages received on GigabitEthernet 1/0/1 are
dropped.
Specify router as the role of the Device A. All RA messages received on GigabitEthernet 1/0/3
are forwarded.
Figure 130 Network diagram
Device B
GE1/0/1
Host
Figure
130, GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 of
Device A
VLAN 10
GE1/0/3
GE1/0/2
Device C
Command
system-view
ipv6 nd raguard log enable
Command
display ipv6 nd raguard policy [ policy-name ]
display ipv6 nd raguard statistics [ interface interface-type
interface-number ]
reset ipv6 nd raguard statistics [ interface interface-type
interface-number ]
442
Remarks
N/A
By default, the RA guard logging
feature is disabled.

Advertisement

Table of Contents
loading

Table of Contents