IPv6 First Hop Security
561
OL-32830-01 Command Line Interface Reference Guide
25
switchxxxxxx(config-ra-guard)#
match ra prefixes prefix-list
list1
switchxxxxxx(config-ra-guard)#
exit
switchxxxxxx(config)#
ipv6 prefix-list list1 deny
2001:0DB8:101::/64
switchxxxxxx(config)#
ipv6 prefix-list list1 permit
2001:0DB8:100::/64
25.57 match reply
To enable verification of the assigned IPv6 addressed in messages sent by
DHCPv6 servers/relays to a configured prefix list within a DHCPv6 Guard policy,
use the match reply command in DHCPv6 Guard Policy Configuration mode. To
return to the default, use the no form of this command.
Syntax
match reply {prefix-list
ipv6-prefix-list-name
} | disable
no match reply
Parameters
•
ipv6-prefix-list-name
—The IPv6 prefix list to be matched.
•
disable—Disables verification of the advertised prefixes in replies.
Default Configuration
Policy attached to port or port channel: the value configured in the policy attached
to the VLAN.
Policy attached to VLAN: advertised prefixes are not verified.
Command Mode
DHCP Guard Policy Configuration mode
User Guidelines
IPv6 DHCP Guard verifies the assigned IPv6 addresses to the configure prefix list
passed in the IA_NA and IA_TA options of the following DHCPv6 messages sent
by DHCPv6 servers/relays:
•
ADVERTISE
•
REPLY
Summary of Contents for 300 Series
Page 2: ......