Specifying The Role Of The Attached Device; Configuring An Ra Guard Policy - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Specifying the role of the attached device

Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet or
aggregate interface view.
3.
Specify the role of the device
attached to the port.

Configuring an RA guard policy

Configure an RA guard policy if you do not specify a role for the attached device or if you want to filter
the RA messages sent by a router.
To configure an RA guard policy:
Step
1.
Enter system view.
2.
Create an RA guard policy
and enter its view.
3.
(Optional.) Specify an ACL
match criterion.
4.
(Optional.) Specify a prefix
match criterion.
5.
(Optional.) Specify a router
preference match criterion.
6.
(Optional.) Specify an M
flag match criterion.
7.
(Optional.) Specify an O flag
match criterion.
8.
(Optional.) Specify a
maximum or minimum hop
limit match criterion.
9.
Quit RA guard policy view.
10. Enter VLAN view.
11. Apply an RA guard policy to
the VLAN.
Command
system-view
interface interface-type
interface-number
ipv6 nd raguard role { host |
router }
Command
system-view
ipv6 nd raguard policy
policy-name
if-match acl
{ ipv6-acl-number | name
ipv6-acl-name }
if-match prefix acl
{ ipv6-acl-number | name
ipv6-acl-name }
if-match router-preference
maximum { high | low |
medium }
if-match autoconfig
managed-address-flag { off
| on }
if-match autoconfig
other-flag { off | on }
if-match hop-limit
{ maximum | minimum } limit
quit
vlan vlan-number
ipv6 nd raguard apply
policy [ policy-name ]
517
Remarks
N/A
N/A
By default, the role of the device
attached to the port is not
specified.
Make sure your setting is
consistent with the device type.
Remarks
N/A
By default, no RA guard policies exist.
If the policy does not contain match
criteria, the policy will not take effect
and the device drops all received RA
messages.
By default, no ACL match criterion
exists.
By default, no prefix match criterion
exists.
By default, no router preference match
criterion exists.
By default, no M flag match criterion
exists.
By default, no O flag match criterion
exists.
By default, no hop limit match criterion
exists.
N/A
N/A
By default, no RA guard policy is
applied to the VLAN.

Advertisement

Table of Contents
loading

Table of Contents