Configuring Ipv6 Ra Guard On An Interface - Cisco Nexus 9000 Series Configuration Manual

Nx-os security configuration guide, release 9.x
Hide thumbs Also See for Nexus 9000 Series:
Table of Contents

Advertisement

Configuring IPv6 RA Guard on an Interface

Command or Action
Step 4
hop-limit {maximum | minimum limit}
Example:
Device(config-ra-guard)# hop-limit minimum 3
Step 5
managed-config-flag {on | off}
Example:
Device(config-ra-guard)# managed-config-flag on
Step 6
other-config-flag {on | off}
Example:
Device(config-ra-guard)# other-config-flag on
Step 7
router-preference maximum {high | low | medium}
Example:
Device(config-ra-guard)# router-preference maximum
high
Step 8
trusted-port
Example:
Device(config-ra-guard)# trusted-port
Step 9
exit
Example:
Device(config-ra-guard)# exit
Configuring IPv6 RA Guard on an Interface
SUMMARY STEPS
1. configure terminal
2. interface type number
3. ipv6 nd raguard attach-policy [policy-name]
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
378
Purpose
• device-role switch—The device-role switch behaves
similar to the device-role host. For example, you can
use it as a label for a trunk port.
• device-role monitor—This device monitors network
traffic. It behaves similar to the device-role host, except
that RS packets are also sent to this interface. This
helps capture traffic.
• device-role router—Interface that connects to the
router. This interface allows incoming RS, RA, or RR
packets.
(Optional) Enables verification of the advertised hop count
limit.
• If not configured, this check will be bypassed.
(Optional) Enables verification that the advertised managed
address configuration flag is on.
• If not configured, this check will be bypassed.
(Optional) Enables verification of the advertised "other"
configuration parameter.
(Optional) Enables verification that the advertised default
router preference parameter value is lower than or equal to
a specified limit.
(Optional) Specifies that this policy is being applied to
trusted ports.
• All RA guard policing will be disabled.
Exits RA guard policy configuration mode and returns to
global configuration mode.
Configuring IPv6 First Hop Security

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents