IPv6 First Hop Security
595
OL-32830-01 Command Line Interface Reference Guide
25
switchxxxxxx(config-ipv6-srcguard)#
exit
25.83 validate source-mac
To enable checking the MAC addresses against the link-layer address within an
IPv6 ND Inspection policy, use the validate source-mac command in ND Inspection
Policy Configuration mode. To return to the default, use the no form of this
command.
Syntax
validate source-mac [enable | disable]
no validate source-mac
Parameters
•
enable—Enables validation of the MAC address against the link-layer
address. If no keyword is configured, this keyword is applied by default.
•
disable—Disables validation of MAC address against the link-layer address.
Default Configuration
Policy attached to port or port channel: the value configured in the policy attached
to the VLAN.
Policy attached to VLAN: global configuration.
Command Mode
ND inspection Policy Configuration mode
User Guidelines
If this command is part of a policy attached to a VLAN, it is applied to all the ports
in the VLAN. If it is defined in a policy attached to a port in the VLAN, this value
overrides the value in the policy attached to the VLAN.
Example
The following example enables the router to drop an NDP message whose
link-layer address does not match the MAC address:
switchxxxxxx(config)#
ipv6 nd inspection policy
policy1
Summary of Contents for 300 Series
Page 2: ......