358
•
IP source guard does not use the VLAN information (if specified) in static IPv6 binding entries to
filter packets.
•
When the ND detection function is configured, be sure to specify the VLAN where ND detection is
configured in static binding entries. Otherwise, ND packets will be discarded because they cannot
match any static IPv6 binding entry.
•
If a static binding entry to be added denotes the same binding as an existing dynamic binding entry,
the new static binding entry overwrites the dynamic binding entry.
To configure a static IPv6 source guard entry on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 interface view.
interface
interface-type
interface-number
N/A
3.
Configure a static IPv6
binding entry on a port.
ipv6 source binding
{
ipv6-address
ipv6-address
|
ipv6-address
ipv6-address
mac-address
mac-address
|
mac-address
mac-address
} [
vlan
vlan-id
]
By default, no static IPv6 binding
entry is configured on a port.
Setting the maximum number of IPv6 source guard entries
The maximum number of IPv6 source guard entries is used to limit the total number of static and dynamic
IPv6 source guard entries on a port. When the number of IPv6 binding entries on a port reaches the
maximum, the port does not allow new IPv6 binding entries any more.
If the maximum number of IPv6 binding entries to be configured is smaller than the number of existing
IPv6 binding entries on the port, the maximum number can be configured successfully, and the existing
entries are not affected. New IPv6 binding entries, however, cannot be added until the number of IPv6
binding entries on the port drops below the configured maximum.
To configure the maximum number of IPv6 binding entries allowed on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Configure the maximum
number of IPv6 binding
entries allowed on the port.
ipv6 verify source max-entries
number
Optional.
By default, the maximum number of
IPv6 source guard entries allowed
on a port is 2048.
Displaying and maintaining IP source guard
For IPv4 source guard: