Dynamic Ipv6 Source Guard Using Nd Snooping Configuration Example - HP 5500 HI Series Configuration Manual

Security
Hide thumbs Also See for 5500 HI Series:
Table of Contents

Advertisement

Configuration procedure
1.
Configure DHCPv6 snooping:
# Enable DHCPv6 snooping globally.
<Device> system-view
[Device] ipv6 dhcp snooping enable
# Enable DHCPv6 snooping in VLAN 2.
[Device] vlan 2
[Device-vlan2] ipv6 dhcp snooping vlan enable
[Device-vlan2] quit
# Configure the port connecting to the DHCP server as a trusted port.
[Device] interface gigabitethernet 1/0/2
[Device-GigabitEthernet1/0/2] ipv6 dhcp snooping trust
[Device-GigabitEthernet1/0/2] quit
2.
Configure the IPv6 source guard function:
# Configure the IPv6 source guard function on GigabitEthernet 1/0/1 to filter packets based on
both the source IP address and MAC address.
[Device] interface gigabitethernet 1/0/1
[Device-GigabitEthernet1/0/1] ipv6 verify source ipv6-address mac-address
[Device-GigabitEthernet1/0/1] quit
Verifying the configuration
# Display the dynamic IPv6 source guard entries generated on port GigabitEthernet 1/0/1.
[Device] display ipv6 source binding
Total entries found: 1
MAC Address
040a-0000-0001
# Display all DHCPv6 snooping entries to see whether they are consistent with the dynamic IP source
guard entries generated on GigabitEthernet 1/0/1.
[Device] display ipv6 dhcp snooping user-binding dynamic
IP Address
============================== ============== ========== ==== ==================
2001::1
---
1 DHCPv6 snooping item(s) found
The output shows that a dynamic IPv6 source guard entry has been generated on port GigabitEthernet
1/0/1 based on the DHCPv6 snooping entry.
Dynamic IPv6 source guard using ND snooping configuration
example
Network requirements
As shown in
Enable ND snooping on the device, establishing ND snooping entries by listening to DAD NS messages.
Enable the IPv6 source guard function on port GigabitEthernet 1/0/1 to filter packets based on the ND
snooping entries, allowing only packets with a legally obtained IPv6 address to pass.
IP Address
2001::1
Figure 1
15, the client is connected to the device through port GigabitEthernet 1/0/1.
VLAN
Interface
2
GE1/0/1
MAC Address
Lease
040a-0000-0001 286
---
365
Type
DHCPv6-SNP
VLAN Interface
2
GigabitEthernet1/0/1

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents