Configuring The Ipv6Sg Feature; Enabling Ipv6Sg On An Interface; Configuring A Static Ipv6Sg Binding - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Exclude IPv4 packets
with the specified
source items from
IPSG filtering.

Configuring the IPv6SG feature

You cannot configure the IPv6SG feature on a service loopback interface. If IPv6SG is enabled on an
interface, you cannot assign the interface to a service loopback group.

Enabling IPv6SG on an interface

When you enable IPv6SG on an interface, the static and dynamic IPv6SG are both enabled.
Static IPv6SG uses static bindings configured by using the ipv6 source binding command.
Dynamic IPv6SG generates dynamic bindings from related source modules. IPv6SG uses the
bindings to filter incoming IPv6 packets based on the matching criteria specified in the ipv6
verify source command.
To implement dynamic IPv6SG, make sure DHCPv6 snooping, DHCPv6 relay agent, or ND
snooping operates correctly on the network.
To enable the IPv6SG feature on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable the IPv6SG
feature.

Configuring a static IPv6SG binding

You can configure global static and interface-specific static IPv6SG bindings.
Global static bindings take effect on all interfaces.
Interface-specific static bindings take priority over global static bindings. An interface first uses the
static bindings on the interface to match packets. If no match is found, the interface uses the global
bindings.
Command
system-view
ip verify source exclude vlan
start-vlan-id [ to end-vlan-id ]
Command
system-view
interface interface-type
interface-number
ipv6 verify source
{ ip-address | ip-address
mac-address | mac-address }
501
Remarks
N/A
By default, no excluded source items are
configured.
You can execute this command multiple
times to specify multiple excluded VLANs.
The specified excluded VLANs cannot
overlap.
Remarks
N/A
The following interface types are
supported:
Layer 2 Ethernet interface.
Layer 3 Ethernet interface.
VLAN interface.
By default, the IPv6SG feature is disabled
on an interface.
If you configure this command on an
interface multiple times, the most recent
configuration takes effect.

Advertisement

Table of Contents
loading

Table of Contents