Enabling Source Mac Consistency Check For Nd Packets; Configuring The Nd Detection Function; Introduction To Nd Detection - HP 3600 v2 Series Security Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

The mapping between the source IPv6 address and the source MAC address in the Ethernet frame
header is invalid.
To identify forged ND packets, HP developed the source MAC consistency check and ND detection
features.
NOTE:
For more information about the five functions of the ND protocol, see
Guide
.
Enabling source MAC consistency check for ND
packets
Use source MAC consistency check on a gateway to filter out ND packets that carry different source
MAC addresses in the Ethernet frame header and the source link layer address option.
Follow these steps to enable source MAC consistency check for ND packets:
To do...
Enter system view
Enable source MAC consistency check for
ND packets
CAUTION:
If VRRP is used, disable source MAC consistency check for ND packets to prevent incorrect dropping of
packets. With VRRP, the NA message always conveys a MAC address different than the Source Link-Layer
Address option.

Configuring the ND detection function

Introduction to ND detection

Use the ND detection function on access devices to verify the source of ND packets. If an ND packet
comes from a spoofing host or gateway, it is discarded.
The ND detection function operates on a per VLAN basis. In an ND detection-enabled VLAN, a port is
either ND-trusted or ND-untrusted:
An ND-trusted port does not check ND packets for address spoofing.
An ND-untrusted port checks all ND packets but RA and RR messages in the VLAN for source
spoofing. RA and RR messages are considered illegal and are discarded directly.
The ND detection function checks an ND packet by looking up the IPv6 static bindings table of the IP
source guard function, ND snooping table, and DHCPv6 snooping table in the following steps:
Looks up the IPv6 static binding table of IP source guard, based on the source IPv6 address and the
1.
source MAC address in the Ethernet frame header of the ND packet. If an exact match is found, the
ND packet is forwarded. If an entry matches the source IPv6 address but not the source MAC
Use the command...
system-view
ipv6 nd mac-check enable
351
Layer 3—IP Services Configuration
Remarks
Required
Disabled by default.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents