IPv6 First Hop Security
533
OL-32830-01 Command Line Interface Reference Guide
25
The policies cannot be attached by the
ipv6 nd raguard attach-policy (port mode)
or
ipv6 nd raguard attach-policy (VLAN mode)
command. The vlan_default policy
is attached by default to a VLAN, if no other policy is attached to the VLAN. The
port_default policy is attached by default to a port, if no other policy is attached to
the port.
You can define a policy using the ipv6 nd raguard policy command multiple times.
If an attached policy is removed, it is detached automatically before removing.
The following commands can be configured in RA Guard Policy Configuration
mode:
•
device-role (RA Guard Policy)
•
hop-limit
•
managed-config-flag
•
match ra addresshop-limit
•
match ra prefixes
•
other-config-flag
•
router-preference
Examples
Example 1—The following example defines an RA Guard policy named policy1,
places the router in RA Guard Policy Configuration mode, and disenabled
validation of the Other Configuration flag, and sets the device role as router:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1
switchxxxxxx(config-ra-guard)#
other-config-flag disable
switchxxxxxx(config-ra-guard)#
device-role router
switchxxxxxx(config-ra-guard)#
exit
Example 2—The following example defines an RA Guard named policy1 using
multiple steps:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1
switchxxxxxx(config-ra-guard)#
other-config-flag disable
Summary of Contents for 300 Series
Page 2: ......