Configuration Guide
NFPP Configuration
ND-guard
ND-guard Overview
ND, the abbreviation of
“Neighbor Discovery”, is responsible for the address
resolution
、
router discovery
、
prefix discovery and the redirection. ND uses the
following 5 types of the ND packets: Neighbor Solicitation
、
Neighbor
Advertisement
、
Router Solicitation
、
Router Advertisement and Redirect, which
are abbreviated as the NS
、
NA
、
RS and RA.
ND Snooping monitors the ND packets in the network, filters the illegal ND
packets and associates the monitored IPv6 users with the interface to prevent
the IPv6 address from being stolen. ND Snooping shall send the ND packets to
the CPU at the configured rate-limit to implement the ND-guard function, for
sending the ND packets at the high rate leads to the CPU attack.
ND-guard classifies the ND packets into the following three types: 1) NS-NA:
the Neighbor Solicitation and the Neighbor Advertisement, used for the address
resolution; 2) RS: the Router Solicitation, used for the gateway discovery by the
host; 3) RA and Redirect: the Router Advertisement and Redirect, used to
advertise the gateway and prefix, and the better next-hop.
At present, only the port-based ND packet attack detection is implemented. You
may configure the rate-limit threshold and the attack threshold for the ND
packets.
When the ND packet rate on a port exceeds the limit, the ND packets are
dropped. When the ND packet rate on a port exceeds the attack threshold limit,
the CLI prompts and the TRAP packets are sent.
ND-guard configuration commands include:
Enabling ND-guard
Port-based rate-limit and attack detection
Showing related dhcpv6-guard information
Enabling ND-guard
You can enable ND-guard in the nfpp configuration mode or in the interface
configuration mode. By default, the ND-guard is enabled.
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie(config)#
nfpp
Enter the nfpp configuration mode.
Ruijie(config-nfpp)#
nd-guard enable
Enable the nd-guard. By default, nd-guard
is enabled.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...