
IPv6 Security RA Configuration
460
debug ipv6 security-ra
no debug ipv6 security-ra
Enable the debug information of IPv6
security RA module, the no operation of
this command will disable the output of
debug information of IPv6 security RA.
show
ipv6
security-ra
[interface
<interface-list>
]
Display the distrust port and whether
globally security RA is enabled.
53.3
IPv6 Security RA Typical Examples
Fig 53-1 IPv6 Security RA sketch map
Instructions: if the illegal user in the graph advertises RA, the normal user will receive
the RA, set the default router as the vicious IPv6 host user and change its own address.
This will cause the normal user to not be able to connect the network. We want to set
security RA on the 1/0/2 port of the switch, so that the RA from the illegal user will not
affect the normal user.
Switch configuration task sequence:
Switch#config
Switch(config)#ipv6 security-ra enable
Switch(Config-If-Ethernet1/0/2)# ipv6 security-ra enable
53.4
IPv6 Security RA Troubleshooting Help
The function of IPv6 security RA is quite simple, if the function does not meet the
PC2
PC1
IPv6 Security RA
RA
Ethernet1/0/1
Ethernet1/0/3
Ethernet1/0/2
RA
X