Purpose
Command or Action
Enables filtering of Router Advertisement messages by the Other
Configuration, or "O" flag field. A rouge RA message with an O field
[
no
]
other-config-flag
{
on
|
off
}
Example:
Switch(config-nd-raguard)#
other-config-flag on
Step 7
of 1 can cause a host to use a rogue DHCPv6 server. If not configured,
this filter is disabled.
On
—
Accepts and forwards RA messages with an O value of 1, blocks
those with 0.
Off
—
Accepts and forwards RA messages with an O value of 0, blocks
those with 1.
Enables filtering of Router Advertisement messages by the Router
Preference flag. If not configured, this filter is disabled.
[
no
]
router-preference maximum
{
high
|
medium
|
low
}
Step 8
Example:
Switch(config-nd-raguard)#
router-preference maximum high
•
high
—
Accepts RA messages with the Router Preference set to
high, medium, or low.
•
medium
—
Blocks RA messages with the Router Preference set
to high.
•
low
—
Blocks RA messages with the Router Preference set to
medium and high.
When configured as a trusted port, all attached devices are trusted,
and no further message verification is performed.
[
no
]
trusted-port
Example:
Switch(config-nd-raguard)#
trusted-port
Step 9
Restores a command to its default value.
default
{
device-role
|
hop-limit
{
maximum
|
minimum
} |
managed-config-flag
|
match
{
ipv6
Step 10
access-list
|
ra prefix-list
} |
other-config-flag
|
router-preference maximum
|
trusted-port
}
Example:
Switch(config-nd-raguard)#
default
hop-limit
(Optional)
—
Displays the ND Guard Policy configuration without
exiting the RA Guard policy configuration mode.
do show ipv6 nd raguard policy policy_name
Example:
Switch(config-nd-raguard)#
do show ipv6
nd raguard policy example_policy
Step 11
How to Attach an IPv6 Router Advertisement Guard Policy to an Interface
Beginning in privileged EXEC mode, follow these steps to attach an IPv6 Router Advertisement policy to an
interface or to VLANs on the interface :
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
456
OL-29048-01
Configuring IPv6 First Hop Security
How to Attach an IPv6 Router Advertisement Guard Policy to an Interface