EasyManua.ls Logo

ELTEX MES3108 - 5.14.3 IPv6 RA Guard Configuration

ELTEX MES3108
243 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
MES3000 Ethernet switch series 87
console(config-tunnel)# tunnel source ip-address 192.168.16.88
5.14.3 IPv6 RA guard configuration
IPv6 RA guard function provides attacks protection based on sending fake Router Advertisement
packets and allows sending messages only from trusted ports.
Global Configuration Mode Commands
Command line request in global configuration mode appears as follows:
console(config)#
Table 5.68Global configuration mode commands
Command
Value/Default value
Action
ipv6 nd raguard
-/disabled
Enable IPv6 RA guard management for the switch.
no ipv6 nd raguard
Disable IPv6 RA guard.
ipv6 nd raguard vlan
vlan
vlan: (1..4094)
Enable IPv6 RA guard management for the switch within the
specified VLAN.
- vlan VLAN number.
Ethernet Interface Configuration Mode Commands
Command line request in the interface configuration mode appears as follows:
console (config-if)#
Table 5.69Ethernet interface configuration mode commands
Command
Value/Default value
Action
ipv6 nd raguard device-role
{host | router }
-/host
Port operation mode selection.
- host block all incoming RA messages;
- router filter RA messages according to the configured rules.
ipv6 nd raguard match access-
list acl
acl: (1..32) characters
Enable ACL for filtering RA messages in router mode.
- acl ACL name.
no ipv6 nd raguard match
access-list
Disable ACL for filtering RA meassages.
ipv6 nd raguard match prefix-
list prefix_list
prefix_list: (1..32)
characters
Enable prefix-list for filtering RA messages in router mode.
- prefix-list prefix-list name.
no ipv6 nd raguard match
prefix-list
Disable prefix-list for filtering RA messages.
ipv6 nd raguard trustedport
By default, all ports are
untrusted
Add port to the trusted list.
no ipv6 nd raguard
trustedport
Delete port from the trusted list.
5.14.4 DHCPv6 guard configuration
The DHCPv6 guard feature prevents third-party DHCPv6 servers on the network and allows their use
only on trusted interfaces.
Global Configuration Mode Commands
Command line request in global configuration mode appears as follows:
console(config)#

Table of Contents

Related product manuals