IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
558
25
no managed-config-flag
Parameters
•
on—The value of the flag must be 1.
•
off—The value of the flag must be 0.
•
disable—The value of the flag is not validated.
Default Configuration
Policy attached to port or port channel: the value configured in the policy attached
to the VLAN.
Policy attached to VLAN: global configuration.
Command Mode
RA Guard Policy Configuration mode
User Guidelines
Use this command to change the global configuration specified by the
ipv6 nd
raguard managed-config-flag
command on the port on which this policy applies.
Use the disable keyword to disable the flag validation in both global or the VLAN
configuration.
Example
The following example defines an RA Guard policy named policy1, places the
switch in RA Guard Policy Configuration mode, and enables M flag verification that
checks if the value of the flag is 0:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1
switchxxxxxx(config-ra-guard)#
managed-config-flag off
switchxxxxxx(config-ra-guard)#
exit
25.55 match ra address
To enable verification of the router's IPv6 address in received RA messages within
an IPv6 RA Guard policy, use the match ra address command in RA Guard Policy
Configuration mode. To return to the default, use the no form of this command.
Summary of Contents for 300 Series
Page 2: ......