Security Level (Ipv6 Snooping) - Cisco Catalyst 3650 series Command Reference Manual

Cisco ios xe everest 16.5.1a
Hide thumbs Also See for Catalyst 3650 series:
Table of Contents

Advertisement

security level (IPv6 snooping)

security level (IPv6 snooping)
To specify the level of security enforced, use the security-level command in IPv6 snooping policy configuration
mode.
security level {glean | guard | inspect}
Syntax Description
glean
guard
inspect
Command Default
The default security level is guard.
Command Modes
IPv6 snooping configuration
Command History
Release
Cisco IOS XE 3.3SECisco IOS XE 3.3SE
Examples
This example shows how to define an IPv6 snooping policy name as policy1, place the device in IPv6 snooping
configuration mode, and configure the security level as inspect:
Device(config)# ipv6 snooping policy policy1
Device(config-ipv6-snooping)# security-level inspect
Command Reference, Cisco IOS XE Everest 16.5.1a (Catalyst 3650 Switches)
798
Extracts addresses from the messages and installs them into the binding
table without performing any verification.
Performs both glean and inspect. Additionally, RA and DHCP server
messages are rejected unless they are received on a trusted port or another
policy authorizes them.
Validates messages for consistency and conformance; in particular, address
ownership is enforced. Invalid messages are dropped.
Modification
This command was introduced.

Advertisement

Table of Contents
loading

Table of Contents