DETAILED STEPS
PurposeCommand or Action
Enters the global configuration mode.configure terminal
Example:
Switch# configure terminal
Step 1
Specifies an interface type and identifier; enters the interface
configuration mode.
interface Interface_type stack/module/port
Example:
Switch(config)# interface gigabitethernet
1/1/4
Step 2
Enters the Switchport mode.switchport
Step 3
Example:
Switch(config-if)# switchport
To configure Layer 2 parameters, if the interface is in Layer
3 mode, you must enter the switchport interface configuration
command without any parameters to put the interface into
Layer 2 mode. This shuts down the interface and then
re-enables it, which might generate messages on the device
to which the interface is connected. When you put an interface
that is in Layer 3 mode into Layer 2 mode, the previous
configuration information related to the affected interface
might be lost, and the interface is returned to its default
configuration. The command prompt displays as (config-if)#
in Switchport configuration mode.
Note
Attaches a custom ipv6 snooping policy to the interface or the specified
VLANs on the interface. To attach the default policy to the interface,
ipv6 snooping [attach-policy policy_name [ vlan
{vlan_id | add vlan_ids | exceptvlan_ids | none |
Step 4
use the ipv6 snooping command without the attach-policy keyword.
remove vlan_ids}] | vlan {vlan_id | add vlan_ids
| exceptvlan_ids | none | remove vlan_ids | all} ]
To attach the default policy to VLANs on the interface, use the ipv6
snooping vlan command. The default policy is, security-level guard,
device-role node, protocol ndp and dhcp.
Example:
Switch(config-if)# ipv6 snooping
or
Switch(config-if)# ipv6 snooping
attach-policy example_policy
or
Switch(config-if)# ipv6 snooping vlan
111,112
or
Switch(config-if)# ipv6 snooping
attach-policy example_policy vlan 111,112
Verifies that the policy is attached to the specified interface without
exiting the interface configuration mode.
do show running-config
Example:
Switch#(config-if)# do show running-config
Step 5
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01 355
Configuring IPv6 First Hop Security
How to Attach an IPv6 Snooping Policy to an Interface or a VLAN on an Interface