IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
496
25
switchxxxxxx(config-ra-guard)#
exit
25.11 drop-unsecure
To enable dropping messages with no or invalid options or an invalid signature
within an IPv6 ND Inspection policy, use the drop-unsecure command in ND
Inspection Policy Configuration mode. To return to the default, use the no form of
this command.
Syntax
drop-unsecure [enable | disable]
no drop-unsecure
Parameters
•
enable—Enables dropping messages with
no or invalid options or an invalid
signature
. If no keyword is configured this keyword is applied by default.
•
disable—Disables dropping messages with no or invalid options or an
invalid signature.
Default Configuration
Policy attached to port or port channel: the value configured in the policy attached
to the VLAN.
Policy attached to VLAN: global configuration.
Command Mode
ND inspection Policy Configuration mode
User Guidelines
If this command is part of a policy attached to a VLAN, it is applied to all the ports
in the VLAN. If it is defined in a policy attached to a port in the VLAN, this value
overrides the value in the policy attached to the VLAN.
Summary of Contents for 300 Series
Page 2: ......