Chapter 49 Ipv6 Security Ra Configuration; Introduction To Ipv6 Security Ra; Security Ra Configuration Task Sequence - Planet WGSW-52040 Configuration Manual

48-port 10/100/1000base-t + 4-port 100/1000x sfp managed switch
Hide thumbs Also See for WGSW-52040:
Table of Contents

Advertisement

49.1 Introduction to IPv6 Security RA

In IPv6 networks, the network topology is generally compromised of routers, layer-two
switches and IPv6 hosts. Routers usually advertise RA, including link prefix, link MTU and
other information, when the IPv6 hosts receive RA, they will create link address, and set the
default router as the one sending RA in order to implement IPv6 network communication. If a
vicious IPv6 host sends RA to cause that normal IPv6 users set the default router as the
vicious IPv6 host user, the vicious user will be able to capture the information of other users,
which will threat the network security. Simultaneously, the normal users get incorrect address
and will not be able to connect to the network. So, in order to implement the security RA
function, configuring on the switch ports to reject vicious RA messages is necessary, thus to
prevent forwarding vicious RA to a certain extent and to avoid affecting the normal operation of
the network.
49.2 IPv6 Security RA Configuration Task Sequence
1. Globally enable IPv6 security RA
2. Enable IPv6 security RA on a port
3. Display and debug the relative information of IPv6 security RA
1. Globally enable IPv6 security RA
Command
Global Configuration Mode
ipv6 security-ra enable
no ipv6 security-ra enable
2. Enable IPv6 security RA on a port
Command
Port Configuration Mode
Chapter 49 IPv6 Security RA
49-186
Configuration
Explanation
Globally enable and disable IPv6 security
RA.
Explanation

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents