User Guide
684
Configuring IPv6 IMPB
Configuration Examples
5
Configuration Examples
5.1 Example for ND Detection
5.1.1 Network Requirements
As shown below, User 1 and User 2 are legal IPv6 users in the LAN and connected to
port 1/0/1 and port 1/0/2. Both of them are in the default VLAN 1. The router has been
configured with security feature to prevent attacks from the WAN. Now the network
administrator wants to configure Switch A to prevent ND attacks from the LAN.
Figure 5-1
Network Topology
LAN
WAN
Fa1/0/3
Fa1/0/1
Fa1/0/2
Router
User 2
88-A9-D4-54-FD-C3
2001::6
User 1
74-D3-45-32-B6-8D
2001::5
Attacker
Switch A
Internet
5.1.2 Configuration Scheme
To meet the requirement, you can configure ND Detection to prevent the network from ND
attacks in the LAN.
The overview of configurations on the switch is as follows:
1) Configure IPv6-MAC Binding. The binding entries for User 1 and User 2 should be
manually bound.
2) Configure ND Detection globally.
Downloaded from