User Guide
682
Configuring IPv6 IMPB
IPv6 Source Guard Configuration
Port
Displays the port number.
Security Type
Select Security Type on the port for IPv6 packets. The following options are
provided:
Disable:
The IP Source Guard feature is disabled on the port.
SIPv6+MAC
: Only the packet with its source IPv6 address, source MAC address
and port number matching the IPv6-MAC binding rules can be processed,
otherwise the packet will be discarded.
SIPv6
: Only the packet with its source IPv6 address and port number matching
the IPv6-MAC binding rules can be processed, otherwise the packet will be
discarded.
LAG
Displays the LAG that the port is in.
2) Click
Apply
.
4.2 Using the CLI
4.2.1 Adding IPv6-MAC Binding Entries
The ND Detection feature allows the switch to detect the ND packets based on the
binding entries in the IPv6-MAC Binding Table and filter out the illegal ND packets. Before
configuring ND Detection, complete IPv6-MAC Binding configuration. For details, refer to
IPv6-MAC Binding Configuration
4.2.2 Configuring IPv6 Source Guard
Before configuring IPv6 Source Guard, you need to configure the SDM template as
EnterpriseV6.
Follow these steps to configure IPv6 Source Guard:
Step 1
configure
Enter global configuration mode.
Step 2
interface { fastEthernet
port |
range fastEthernet
port-list |
gigabitEthernet
port |
range
gigabitEthernet
port-list
|
ten-gigabitEthernet
port |
range ten-gigabitEthernet
port-list
}
Enter interface configuration mode.
Step 3
ipv6 verify source {
sipv6+mac | sipv6
}
Enable IPv6 Source Guard for IPv6 packets.
sipv6+mac
:
Only the packet with its source IP address, source MAC address and port
number matching the IPv6-MAC binding rules can be processed, otherwise the packet will
be discarded.
Downloaded from