![Cisco 300 Series Скачать руководство пользователя страница 553](http://html.mh-extra.com/html/cisco/300-series/300-series_cli-manual_67483553.webp)
IPv6 First Hop Security
553
OL-32830-01 Command Line Interface Reference Guide
25
User Guidelines
Use this command to attach an IPv6 Source Guard policy to a port.
Each succeeding ipv6 source guard attach-policy command overrides the
previous policy attachment on the same port.
IPv6 Source guard policies can be used to block forwarding IPv6 data messages
with unknown source IPv6 addresses or with source IPv6 addresses bound to a
port differing from the input one.
If a policy specified by the
policy-name
argument is not defined, the command is
rejected.
The set of rules that is applied to an input packet is built in the following way:
•
The rules, configured in the policy attached to the port.
•
The global rules are added to the set if they have not been added.
Use the no ipv6 source guard attach-policy command to detach the user defined policy
attached to the port and to reattach the default policy with name "port_default".
Examples
Example 1—In the following example, the IPv6 Source Guard policy policy1 is
attached to the gi11 port:
switchxxxxxx(config)#
interface
gi11
switchxxxxxx(config-if)#
ipv6 source guard attach-policy
policy1
switchxxxxxx(config-if)#
exit
Example 2—In the following example IPv6 Source Guard detaches policy1 from
the gi11 port:
switchxxxxxx(config)#
interface
gi11
switchxxxxxx(config-if)#
no ipv6 source guard attach-policy
switchxxxxxx(config-if)# exit
Содержание 300 Series
Страница 2: ......