Static Ipv6 Source Guard Configuration Example - HP 6125XLG Configuration Manual

Blade switch security configuration guide
Table of Contents

Advertisement

Static IPv6 source guard configuration example

Network requirements
As shown in
Configure a static IPv6 source guard binding entry for Ten-GigabitEthernet 1/1/5 of the switch to allow
only IPv6 packets from the host to pass.
Figure 60 Network diagram
Configuration procedure
# Enable IPv6 source guard on port Ten-GigabitEthernet 1/1/5.
<Switch> system-view
[Switch] interface ten-gigabitEthernet 1/1/5
[Switch-Ten-GigabitEthernet1/1/5] ipv6 verify source ip-address mac-address
# On port Ten-GigabitEthernet 1/1/5, configure a static IPv6 source guard binding entry to allow only
IPv6 packets with the source IPv6 address of 2001::1 and the source MAC address of 00-01-02-02-02-02
to pass.
[Switch-Ten-GigabitEthernet1/1/5] ipv6 source binding ip-address 2001::1 mac-address
0001-0202-0202
[Switch-Ten-GigabitEthernet1/1/5] quit
Verifying the configuration
# Display static IPv6 source guard binding entries on the switch. The output shows that a static binding
entry is configured successfully.
[Switch] display ipv6 source binding static
Total entries found: 1
IPv6 Address
2001::1
Figure
60, the host is connected to port Ten-GigabitEthernet 1/1/5 of the switch.
MAC Address
0001-0202-0202 XGE1/1/5
Interface
170
VLAN Type
N/A
Static

Advertisement

Table of Contents
loading

Table of Contents