Configuration Guidelines; Configuration Procedure; Displaying And Maintaining Nd Detection - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

source IPv6 address, the ND detection function continues to look up the DHCPv6 snooping table
and the ND snooping table.
If a match is found in either the DHCPv6 snooping or ND snooping table, the ND packet is
considered legal and forwarded. If no match is found in either table, the packet is considered
illegal and discarded directly.

Configuration guidelines

Follow these guidelines when you configure the ND detection function:
The IPv6 static bindings of IP source guard can be created with the ipv6 source binding command.
For more information, see
The DHCPv6 snooping table is created automatically by the DHCPv6 snooping module. For more
information, see Layer 3—IP Services Configuration Guide.
The ND snooping table is created automatically by the ND snooping module. For more information,
see Layer 3—IP Services Configuration Guide.
Source check performed by ND detection depends on the binding tables of IP source guard,
DHCPv6 snooping, and ND snooping. To prevent legal ND packets from being discarded on an
ND-untrusted port in an ND detection-enabled VLAN, make sure at least one of the three functions
is available.
When creating an IPv6 static binding with IP source guard for ND detection in a VLAN, specify the
VLAN ID for the binding. Otherwise, no ND packets in the VLAN can match the binding.
The switch supports ND detection only when you configure the acl ipv6 enable command. For more
information about this command, see ACL and QoS Command Reference.

Configuration procedure

To configure ND detection:
Step
Enter system view.
1.
2.
Enter VLAN view.
3.
Enable ND Detection.
4.
Quit system view.
5.
Enter
interface view or Layer 2
aggregate interface view.
6.
Configure the port as an
ND-trusted port.

Displaying and maintaining ND detection

"Configuring IP source
Command
system-view
vlan vlan-id
ipv6 nd detection enable
quit
Layer
2
Ethernet
interface interface-type
interface-number
ipv6 nd detection trust
guard."
284
Remarks
N/A
N/A
By default, ND detection is disabled
from checking ND packets.
N/A
N/A
Optional.
A port does not trust sources of ND
packets by default.

Advertisement

Table of Contents
loading

Table of Contents