Chapter 54 Ipv6 Security Ra Configuration; Introduction To Ipv6 Security Ra; Ra C Onfiguration T Ask S Equence - Planet XGS3-42000R User Manual

4-slot layer 3 ipv6/ ipv4 routing chassis switch
Table of Contents

Advertisement

Chapter 54 IPv6 Security RA Configuration

54.1 Introduction to IPv6 Security RA

In IP v6 networks, the network topology is generally compromised of rout ers, layer-t wo switches and IP v6
hosts. Routers usually advertise RA, including link prefix, link MTU and other information, when the IP v6 hosts
receive RA, they will create link address, and set the default router as the one sending RA in order to
implement IP v6 network communication. If a vicious IP v6 host sends RA to cause that normal IP v6 users set
the default router as the vicious IP v6 host user, the vicious user will be able to capture the information of other
users, which will threat the net work security. Simultaneously, the normal users get incorrect address and will
not be able to connect to the network. So, in order to implement the security RA function, configuring on the
switch ports to reject vicious RA messages is necessary, thus to prevent forwarding vicious RA to a certain
extent and to avoid affecting the normal operation of the net work.
54.2 IPv6 Security RA Configuration Task Sequence
1.
Globally enable IP v6 security RA
2.
Enable IP v6 security RA on a port
3.
Display and debug the relative information of IP v6 security RA
1. Globally enable IPv6 security RA
Global Configuration Mode
ipv6 security-ra enable
no ipv6 security-ra enable
2. Enable IPv6 security RA on a port
Port Configuration Mode
ipv6 security-ra enable
no ipv6 security-ra enable
3. Di splay and debug the relative information of IPv6 securi ty RA
Admin Mode
debug ipv6 security-ra
no debug ipv6 security-ra
show
ipv6
<interface-li st>]
Command
Command
Command
security-ra
[interface
Explanation
Globally enable and disable IP v6 security
RA.
Explanation
Enable and disable IP v6 security RA in port
configuration mode.
Explanation
Enable the debug information of IP v6
security RA module, the no operation of
this command will disable the output of
debug information of IP v6 security RA.
Display the distrust port and whether
globally security RA is enabled.
54-1

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents