DETAILED STEPS
Purpose
Command or Action
Enters the global configuration mode.
configure terminal
Example:
Switch#
configure terminal
Step 1
Specifies an interface type and identifier; enters the
interface configuration mode.
interface
Interface_type
stack/module/port
Example:
Switch(config)#
interface gigabitethernet 1/1/4
Step 2
Attaches the Neighbor Discovery Inspection policy
to the interface or the specified VLANs on that
ipv6 dhcp guard
[
attach-policy policy_name
[
vlan
{
vlan_ids
|
add vlan_ids
|
except vlan_ids
|
none
|
remove vlan_ids
|
all
} ]
Step 3
interface. The default policy is attached if the
attach-policy
option is not used.
|
vlan
[ {
vlan_id
s |
add vlan_ids
|
exceptvlan_ids
|
none
|
remove
vlan_ids
|
all
} ]
Example:
Switch(config-if)#
ipv6 dhcp guard attach-policy
example_policy
or
Switch(config-if)#
ipv6 dhcp guard attach-policy
example_policy vlan 222,223,224
or
Switch(config-if)#
ipv6 dhcp guard vlan 222, 223,224
Confirms that the policy is attached to the specified
interface without exiting the configuration mode.
do show running-config
Example:
Switch#(config-if)#
do show running-config
Step 4
How to Attach an IPv6 DHCP Guard Policy to VLANs Globally
Beginning in privileged EXEC mode, follow these steps to attach an IPv6 DHCP Guard policy to VLANs
across multiple interfaces:
SUMMARY STEPS
1.
configure terminal
2.
vlan configuration vlan_list
3.
ipv6 dhcp guard
[
attach-policy policy_name
]
4.
do show running-config
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
368
OL-29434-01
Configuring IPv6 First Hop Security
How to Attach an IPv6 DHCP Guard Policy to VLANs Globally