3-7
IPv6 Management Security Features
Authorized IP Managers for IPv6
to 0 (“off”) and allow the corresponding bits in an authorized IPv6 address to
be either “on” or “off”. As a result, only the four IPv6 addresses shown in Figure
3-5 are allowed access.
Figure 3-5. Example: How Hexadecimal C in a Mask Authorizes Four IPv6 Manager Addresses
Example.
Figure 3-6 shows an example in which a mask is applied to the
IPv6 address:
2001:DB8:0000:0000:244:17FF:FEB6:D37D/64
. The specified mask
FFFF:FFFF:FFFF:FFF8:FFFF:FFFF:FFFF:FFFF
configures eight management stations as
authorized IP manager stations.
Note that, in this example, the IPv6 mask is applied as follows:
■
Eight management stations in different subnets are authorized by the
value of the fourth block (
FFF8
) in the 64-bit prefix ID (
FFFF:FFFF:FFFF:FFF8
)
of the mask. (The fourth block of the prefix ID is often used to define
subnets in an IPv6 network.)
The binary equivalent of
FFF8
that is used to specify valid subnet IDs in the
IPv6 addresses of authorized stations is: 1111 1111 1111 1000.
The three “off” bits (1000) in the last part of the this block (
FFF8
) of the
mask allow for eight possible authorized IPv6 stations:
2001:DB8:0000:0000:244:17FF:FEB6:D37D
2001:DB8:0000:0001:244:17FF:FEB6:D37D
2001:DB8:0000:0002:244:17FF:FEB6:D37D
2001:DB8:0000:0003:244:17FF:FEB6:D37D
2001:DB8:0000:0004:244:17FF:FEB6:D37D
2001:DB8:0000:0005:244:17FF:FEB6:D37D
2001:DB8:0000:0006:244:17FF:FEB6:D37D
2001:DB8:0000:0007:244:17FF:FEB6:D37D
■
Each authorized station has the same 64-bit device ID (
244:17FF:FEB6:D37D
)
because the value of the last four blocks in the mask is
FFFF
(binary value
1111 1111).
1st
Block
2nd
Block
3rd
Block
4th
Block
5th
Block
6th
Block
7th
Block
8th
Block
IPv6 Mask
FFFF
FFFF
FFFF
FFFF
FFFF
FFFF
FFFF
FFFC
IPv6 Address Entered with the “ipv6
authorized-managers” Command
2001
DB8
0000
0000
244
17FF
FEB6
D37D
Other Authorized IPv6 Addresses
2001
DB8
0000
0000
244
17FF
FEB6
D37C
2001
DB8
0000
0000
244
17FF
FEB6
D37E
2001
DB8
0000
0000
244
17FF
FEB6
D37F
Содержание 2520-24
Страница 2: ......
Страница 3: ...HP Networking 2520 Switches IPv6 Configuration Guide August 2012 S 15 09 ...
Страница 8: ......
Страница 42: ...1 30 IPv6 Addressing Configuration Address Lifetimes ...
Страница 102: ...A 2 IPv6 Terminology ...
Страница 109: ......