Security Planning
Security planning includes system security, user security, and service security, ensuring user
services are provided properly from different dimensions.
In the FTTH (gateway ONT) networking scenario, only anti-IP spoofing and DHCP option of
IPv6 and IPv4 services are different.
Anti-IP spoofing: This function needs to be configured separately for IPv6 services.
The anti-IP spoofing function can be enabled or disabled at three levels. This function takes
effect only when it is enabled at all the three levels.
1.
Global level: Run the
security anti-ipv6spoofing enable
command in global config mode.
2.
VLAN level: Run the
security anti-ipv6spoofing enable
command in VLAN service
profile mode.
3.
Service port level: Run the
security anti-ipv6spoofing service-port serviceport-id
enable
command.
DHCP option: The DHCP option for IPv4 is DHCPv4 option 82 and for IPv6 is DHCPv6 option
18/37.
The DHCPv6 option18 and option37 functions can be enabled or disabled at two levels. This
function takes effect only when it is enabled at both levels.
1.
Global level: Run the
dhcpv6 option enable
command in global config mode.
2.
VLAN level: Run the
dhcpv6 option enable
command in VLAN service profile mode.
Device Management Data Planning
Device management data planning includes the management channel and IP address planning.
The management channel for IPv6 and IPv4 services are the same.
Planning
Device or Service Solution Introduction
Management
channel
OLT
The device management uses single-tagged VLANs
on the entire network.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
19 IPv6 Configuration
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1936