Chapter 24: General Security Measures
IPv6 Source Guard
– 874 –
entries discovered by ND snooping, DHCPv6 snooping, and static
entries set by the
•
IPv6 source guard maximum bindings must be set to a value higher
than DHCPv6 snooping maximum bindings and ND snooping maximum
bindings.
•
If IPv6 source guard, ND snooping, and DHCPv6 snooping are enabled
on a port, the dynamic bindings used by ND snooping, DHCPv6
snooping, and IPv6 source guard static bindings cannot exceed the
maximum allowed bindings set by the
ipv6 source-guard max-
binding
command. In other words, no new entries will be added to the
IPv6 source guard binding table.
•
If IPv6 source guard is enabled on a port, and the maximum number of
allowed bindings is changed to a lower value, precedence is given to
deleting entries learned through DHCPv6 snooping, ND snooping, and
then manually configured IPv6 source guard static bindings, until the
number of entries in the binding table reaches the newly configured
maximum number of allowed bindings.
E
XAMPLE
This example sets the maximum number of allowed entries in the binding
table for port 5 to one entry.
Console(config)#interface ethernet 1/5
Console(config-if)#ipv6 source-guard max-binding 1
Console(config-if)#
show ipv6
source-guard
This command shows whether IPv6 source guard is enabled or disabled on
each interface, and the maximum allowed bindings.
C
OMMAND
M
ODE
Privileged Exec
E
XAMPLE
Console#show ipv6 source-guard
Interface Filter-type Max-binding
--------- ----------- -----------
Eth 1/1 DISABLED 5
Eth 1/2 DISABLED 5
Eth 1/3 DISABLED 5
Eth 1/4 DISABLED 5
Eth 1/5 SIP 1
Eth 1/6 DISABLED 5
.
.
.
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...