452
Configuration procedure
# Enable IPv6SG on Ten-GigabitEthernet 1/0/1.
<Device> system-view
[Device] interface ten-gigabitethernet 1/0/1
[Device-Ten-GigabitEthernet1/0/1] ipv6 verify source ip-address mac-address
# On Ten-GigabitEthernet 1/0/1, configure a static IPv6SG binding for the host.
[Device-Ten-GigabitEthernet1/0/1] ipv6 source binding ip-address 2001::1 mac-address
0001-0202-0202
[Device-Ten-GigabitEthernet1/0/1] quit
Verifying the configuration
# Verify that the static IPv6SG binding is configured successfully on the device.
[Device] display ipv6 source binding static
Total entries found: 1
IPv6 Address MAC Address Interface VLAN Type
2001::1 0001-0202-0202 XGE1/0/1 N/A Static
Dynamic IPv6SG using DHCPv6 snooping configuration
example
Network requirements
As shown in
, the host (the DHCPv6 client) obtains an IP address from the DHCPv6 server.
Perform the following tasks:
•
Enable DHCPv6 snooping on the device to make sure the DHCPv6 client obtains an IPv6
address from the authorized DHCPv6 server. To generate a DHCPv6 snooping entry for the
DHCPv6 client, enable recording of client information in DHCPv6 snooping entries.
•
Enable dynamic IPv6SG on Ten-GigabitEthernet 1/0/1 to filter incoming packets by using the
IPv6SG bindings generated based on DHCPv6 snooping entries. Only packets from the
DHCPv6 client are allowed to pass.
Figure 126 Network diagram
Configuration procedure
1.
Configure DHCPv6 snooping:
# Enable DHCPv6 snooping globally.
<Device> system-view
[Device] ipv6 dhcp snooping enable
# Configure Ten-GigabitEthernet 1/0/2 as a trusted interface.
[Device] interface ten-gigabitethernet 1/0/2
[Device-Ten-GigabitEthernet1/0/2] ipv6 dhcp snooping trust
[Device-Ten-GigabitEthernet1/0/2] quit
2.
Enable IPv6SG:
# Enable IPv6SG on Ten-GigabitEthernet 1/0/1 and verify the source IP address and MAC
address for dynamic IPv6SG.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...