EasyManuals Logo

Cisco 300 Series User Manual

Cisco 300 Series
1117 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #560 background imageLoading...
Page #560 background image
IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide 560
25
25.56 match ra prefixes
To enable verification of the advertised prefixes in received RA messages within
an IPv6 RA Guard policy, use the match ra prefixes command in RA Guard Policy
Configuration mode. To return to the default, use the no form of this command.
Syntax
match ra prefixes {prefix-list
ipv6-prefix-list-name
} | disable
no match ra prefixes
Parameters
• prefix-list
ipv6-prefix-list-name
—The IPv6 prefix list to be matched.
• disable—Disables verification of the advertised prefixes in received RA
messages.
Default Configuration
Policy attached to port or port channel: the value configured in the policy attached
to the VLAN.
Policy attached to VLAN: advertised prefixes are not verified.
Command Mode
RA Guard Policy Configuration mode
User Guidelines
This command enables verification of the advertised prefixes in received RA
messages by a configured prefix list. If an advertised prefix does not match the
prefix list, or if the prefix list is not configured, the RA message is dropped.
Use the disable keyword to disable verification of the advertised prefixes in
received RA messages in both global or the VLAN configuration.
Example
The following example defines an RA Guard policy named policy1, places the
switch in RA Guard configuration mode, matches the prefixes to the prefix list
named list1, and the 2001:101::/64 prefixes and denies 2001:100::/64 prefixes:
switchxxxxxx(config)#
ipv6 nd raguard policy
policy1

Table of Contents

Other manuals for Cisco 300 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 300 Series and is the answer not in the manual?

Cisco 300 Series Specifications

General IconGeneral
ModelCisco 300 Series
CategorySwitch
DimensionsVaries by model
WeightVaries by model
Power over Ethernet (PoE)Available on select models
ManagementWeb-based GUI, SNMP, CLI
VLANsUp to 256
Security FeaturesACLs, 802.1X, Port Security
Humidity10% to 90% non-condensing
Ports8, 16, 24, 48

Related product manuals