PurposeCommand or Action
Attaches a DHCPv6 guard policy to a VLAN.
ipv6 dhcp guard [attach-policy policy-name]
Example:
Step 13
Device(config-vlan-config)# ipv6 dhcp guard
attach-policy pol1
Exits VLAN configuration mode and returns to global
configuration mode.
exit
Example:
Step 14
Device(config-vlan-config)# exit
Exits global configuration mode and returns to privileged
EXEC mode.
exit
Example:
Step 15
Device(config)# exit
(Optional) Displays the policy configuration as well as all
the interfaces where the policy is applied.
show ipv6 dhcp guard policy [policy-name]
Example:
Step 16
Device# show ipv6 dhcp policy guard pol1
Configuring IPv6 Snooping
SUMMARY STEPS
1. configure terminal
2. ipv6 snooping policy policy-name
3. device-role { node | switch }
4. [no] limit address-count
5. [no] protocol dhcp | ndp
6. trusted-port
7. security-level glean | guard | inspect
8. tracking
9. exit
10. interface type-number
11. [no] switchport
12. ipv6 snooping attach-policy policy-name
13. exit
14. vlan configuration vlan-id
15. ipv6 snooping attach-policy policy-name
16. exit
17. exit
18. show ipv6 snooping policy policy-name
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
382
Configuring IPv6 First Hop Security
Configuring IPv6 Snooping