1-23
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
OL-25303-03
Chapter 1 Configuring IPv6 Unicast Routing
Configuring IPv6
Here, 2/1/2 is a router-facing port:
Switch(config)# interface fastethernet 2/1/2
Switch(config-if)# switchport
Switch(config-if)# swithport access vlan 100
Switch(config-if)# ipv6 nd raguard attach-policy router
Switch(config-if)# exit
Here, 1/0/17 is a DHCP server-facing port:
Switch(config)# interface gigabitethernet 1/0/17
Switch(config-if)# switchport access vlan 100
Switch(config-if)# ipv6 dhcp guard attach-policy server
Switch(config-if)# exit
Switch(config)# exit
Switch# show ipv6 snooping policies
Target Type Policy Feature Target range
Gi1/0/17 PORT server DHCP Guard vlan all
Te2/1/2 PORT router RA guard vlan all
vlan 100 VLAN default Snooping vlan all
This example shows you how to create a snooping policy called Test and enable data address gleaning
on it:
Switch(config)# ipv6 snooping policy Test
Switch(config-ipv6-snooping)# data-glean
Switch(config-ipv6-snooping)# device-role node
Switch(config-ipv6-snooping)# limit address-count 1
Switch(config-ipv6-snooping)# protocol dhcp
Switch(config-ipv6-snooping)# security-level glean
Switch(config-ipv6-snooping)# tracking enable
Switch(config-ipv6-snooping)# no trusted-port
Switch(config-ipv6-snooping)# exit
This example shows you how to configure snooping policy Tes t, enable data address gleaning on the
policy, and enable source guard where link-local addresses are permitted and global autoconfiguration
addresses are denied entry:
Switch(config)# ipv6 snooping policy Test
Switch(config-ipv6-snooping)# data-glean
Switch(config-ipv6-snooping)# exit
Switch(config)# ipv6 source-guard policy Test
Switch(config-sisf-sourceguard)# permit link-local
Switch(config-sisf-sourceguard)# deny global-autoconf
Switch(config-sisf-sourceguard)# exit
This example shows you how to attach a snooping policy with source guard, to an interface:
Switch(config)# interface gigabitethernet2/0/3
Switch(config-if)# ipv6 snooping attach-policy Test
Switch(config-if)# ipv6 source-guard attach-policy Test
Switch# show ipv6 source-guard policy Test
Policy Test configuration:
permit link-local
deny global-autoconf
Policy Test is applied on the following targets:
Target Type Policy Feature Target range
Gi2/0/3 PORT Test Source guard vlan all