Chapter 27 Nd Snooping Configuration; Introduction To Nd Snooping; Nd Snooping Basic Configuration - Planet XGS3-42000R User Manual

4-slot layer 3 ipv6/ ipv4 routing chassis switch
Table of Contents

Advertisement

Chapter 27 ND Snooping Configuration

27.1 Introduction to ND Snooping

The purpose of developing ND snooping module: using Control Packet Snooping (CPS ) mechanism, that
means to detect the validity of access packets through the method which bind the source IP v6 address and
the anchor information, so as to permit the matched packets and drop the unmatched packets that will control
access of the direct connected IP v6 nodes. The development of this module requirement refers to IP v6 NDP
and 《 Control Packet Snooping Based Binding draft-bi-savi-cps-00 》 draft. ND snooping adopts the
"first-come first-serve" of the 《 First-Come First-Serve S ourc e-Address Validation Implementation
draft-iet f-savi-fcfs-01》 draft that means to set up the first bound nodes as the legality nodes, and it is a
principle to check the validity of the nodes.
ND snooping is mostly applied to the access device (such as layer 2 switch, wireless access node). The
access device creat es the binding information table of link-local nodes (the binding refers to the IP v6 address
and the port ID and the MA C address of the nodes) according to the NDP packets received from theses ports,
then creates the rules of FFP (Fast Filter Processor) hardware drive according to the binding information table,
and implements the access control of the link-local nodes.

27.2 ND Snooping Basic Configuration

ND Snooping Configuration Task List:
1. Enable or disable the monitor function of ND Snooping
2. Configure the lifetime of ND Snooping
1)
Set the binding lifetime of SAC_B OUND state
2)
Set the binding lifetime of SAC_S TA RT state
3)
Set the binding lifetime of SAC-QUE RY state
3. The binding function of ND Snooping
1)
Configure the dynamic binding policy of ND Snooping address
2)
Add a static binding
3)
Configure the max number of IP v6 addresses that can be bound to the same MA C address
4)
Set the max binding number for the ports
5)
Clear all dynamic bindings of ND Snooping
4. Set the trust port of the switch
1. Enable or disable the monitor function of ND Snooping
Global mode
ipv6 nd snooping enable
no ipv6 nd snooping enable
Port mode
ipv6 nd snooping user-control
no ipv6 nd snooping user-control
Command
27-1
Expalnation
Enable or disable ND Snooping
globally.
Enable or disable ND Snooping in a
port.

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents