IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
498
25
Command Mode
RA Guard Policy Configuration mode
User Guidelines
If this command is part of a policy attached to a VLAN, it is applied to all the ports
in the VLAN. If it is defined in a policy attached to a port in the VLAN, this value
overrides the value in the policy attached to the VLAN.
Use the disable keyword to disable verification regardless of the global or VLAN
configuration.
Examples
Example 1—The following example defines an RA Guard policy named policy1,
places the switch in RA Guard Policy Configuration mode, and defines a minimum
Cur Hop Limit value of 5:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1
switchxxxxxx(config-ra-guard)#
hop-limit minimum 5
switchxxxxxx(config-ra-guard)#
exit
Example 2—The following example defines an RA Guard policy named policy1,
places the switch in RA Guard Policy Configuration mode, and disables validation
of the Cur Hop Limit high boundary:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1
switchxxxxxx(config-ra-guard)#
hop-limit maximum disable
switchxxxxxx(config-ra-guard)#
exit
25.13 ipv6 dhcp guard
To enable the DHCPv6 guard feature on a VLAN, use the ipv6 dhcp guard
command in VLAN Configuration mode. To return to the default, use the no form of
this command.
Syntax
ipv6 dhcp guard
Summary of Contents for 300 Series
Page 2: ......