IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
538
25
-
stateless—IPv6 addresses are bound from NDP messages, and only
global addresses belonging to learned prefixes with set A-flag or
prefixes manually configured with the autoconfig keyword are allowed.
-
any—IPv6 addresses are bound from NDP messages and only global
addresses belonging to prefixes in NPT are allowed.
Use the dhcp keyword, to allow binding from DHCPv6 message. IPv6 addresses
bound from DHCPv6 messages are never verified against the Neighbor Prefix
table. IPv6 addresses bound from DHCPv6 messages override IPv6 addresses
bound from NDP messages.
Note. If the dhcp keyword is not configured, the switch will bind IPv6 addresses
assigned by DHCPv6 from NDP messages, because a host must execute the DAD
process for these addresses.
If no keyword is defined the ipv6 neighbor binding address-config any command
is applied.
Examples
Example 1. The following example specifies that any global IPv6 address
configuration method can be applied and there will be no binding from DHCPv6
messages:
switchxxxxxx(config)#
ipv6 neighbor binding address-prefix-validation
switchxxxxxx(config)#
ipv6 neighbor binding address-config any
Example 2. The following example specifies that any global IPv6 address binding
from NDP and global IPv6 address binding from DHCPv6 messages can be
applied:
switchxxxxxx(config)#
ipv6 neighbor binding address-prefix-validation
switchxxxxxx(config)#
ipv6 neighbor binding address-config any dhcp
Example 3. The following example specifies that only stateless global IPv6
address binding from NDP can be applied
switchxxxxxx(config)#
ipv6 neighbor binding address-prefix-validation
Summary of Contents for 300 Series
Page 2: ......