Chapter 24: General Security Measures
IPv6 Source Guard
– 870 –
IP
V
6 S
OURCE
G
UARD
IPv6 Source Guard is a security feature that filters IPv6 traffic on non-
routed, Layer 2 network interfaces based on manually configured entries in
the IPv6 Source Guard table, or dynamic entries in the Neighbor Discovery
Snooping table or DHCPv6 Snooping table when either snooping protocol is
). IPv6 source guard can be
used to prevent traffic attacks caused when a host tries to use the IPv6
address of a neighbor to access the network. This section describes
commands used to configure IPv6 Source Guard.
ipv6 source-guard
binding
This command adds a static address to the source-guard binding table. Use
the
no
form to remove a static entry.
S
YNTAX
ipv6 source-guard binding
mac-address
vlan vlan-id ipv6-address
interface interface
no
ipv6 source-guard
binding mac-address
vlan vlan-id
mac-address
- A valid unicast MAC address.
vlan-id
- ID of a configured VLAN (Range: 1-4094)
ipv6-address
- Corresponding IPv6 address. This address must be
entered according to RFC 2373 “IPv6 Addressing Architecture,”
using 8 colon-separated 16-bit hexadecimal values. One double
colon may be used in the address to indicate the appropriate
number of zeros required to fill the undefined fields.
interface
ethernet
unit
/
port
unit
- Unit identifier. (Range: 1)
port
- Port number. (Range: 1-52)
D
EFAULT
S
ETTING
No configured entries
Table 24-11: IPv6 Source Guard Commands
Command
Function
Mode
Adds a static address to the source-guard binding
table
GC
Configures the switch to filter inbound traffic based
on source IP address
IC
Sets the maximum number of entries that can be
bound to an interface
IC
Shows whether source guard is enabled or disabled
on each interface
PE
Shows the source guard binding table
PE
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...