Configuring Ra Guard; About Ra Guard; Specifying The Role Of The Attached Device - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

[DeviceB] interface gigabitethernet 1/0/2
[DeviceB-GigabitEthernet1/0/2] port link-type access
[DeviceB-GigabitEthernet1/0/2] port access vlan 10
[DeviceB-GigabitEthernet1/0/2] quit
[DeviceB] interface gigabitethernet 1/0/3
[DeviceB-GigabitEthernet1/0/3] port link-type trunk
[DeviceB-GigabitEthernet1/0/3] port trunk permit vlan 10
[DeviceB-GigabitEthernet1/0/3] quit
# Enable ND attack detection for VLAN 10.
[DeviceB] vlan 10
[DeviceB-vlan10] ipv6 nd detection enable
# Enable ND snooping for IPv6 global unicast addresses and ND snooping for IPv6 link-local
addresses in VLAN 10.
[DeviceB-vlan10] ipv6 nd snooping enable global
[DeviceB-vlan10] ipv6 nd snooping enable link-local
[DeviceB-vlan10] quit
# Configure GigabitEthernet 1/0/3 as ND trusted interface.
[DeviceB] interface gigabitethernet 1/0/3
[DeviceB-GigabitEthernet1/0/3] ipv6 nd detection trust
The configuration allows Device B to inspect all ND messages received by GigabitEthernet 1/0/1 and
GigabitEthernet 1/0/2 based on the ND snooping entries.

Configuring RA guard

About RA guard

RA guard allows Layer 2 access devices to analyze and block unwanted and forged RA messages.
Upon receiving an RA message, the device makes the forwarding or dropping decision based on the
role of the attached device or the RA guard policy.
1.
If the role of the device attached to the port is router, the device forwards all RA messages
received on the port. If the role is host, the device directly drops all RA messages received on
the port.
2.
If no role is set for the port, the device uses the RA guard policy to match the information found
in the RA message.
If the RA message content matches every criterion in the policy, the device forwards the
message.
If the RA message content is not validated, the device drops the message.

Specifying the role of the attached device

Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet or
aggregate interface view.
Command
system-view
interface interface-type
interface-number
535
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents