IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
526
25
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
Use this command to attach an RA Guard policy to a port.
Each time the command is used, it overrides the previous command within the
same policy.
If a policy specified by the
policy-name
argument is not defined, the command is
rejected.
Multiple policies with the vlan keyword can be attached to the same port if they
do not have common VLANs.
The set of rules that is applied to an input packet is built in the following way:
•
The rules, configured in the policy attached to the port on the VLAN on
which the packet arrived are added to the set.
•
The rules, configured in the policy attached to the VLAN are added to the
set if they have not been added.
•
The global rules are added to the set if they have not been added.
Use the no ipv6 nd raguard attach-policy command to detach all user-defined
policies attached to the port.
Use the no ipv6 nd raguard attach-policy
policy-name
command to detach the
specific policy from the port.
Examples
Example 1—In the following example, the RA Guard policy policy1 is attached to
the gi11 port:
switchxxxxxx(config)#
interface
gi11
switchxxxxxx(config-if)#
ipv6 nd raguard attach-policy
policy1
switchxxxxxx(config-if)#
exit
Example 2—In the following example, the RA Guard policy policy1 is attached to
the gi11 port and applied to VLANs 1-10 and 12-20:
switchxxxxxx(config)#
interface
gi11
Содержание 300 Series
Страница 2: ......