295
NOTE:
• To implement dynamic IPv6 source guard, make sure that DHCPv6 snooping or ND snooping is
configured and works normally. For DHCPv6 and ND snooping configuration information, see the
Laye
3—IP Services Configuration Guide
.
• If you configure dynamic IPv6 source guard on a port for multiple times, the last configuration will
overwrite the previous configuration on the port.
• If you confi
ure both ND snoopin
and DHCPv6 snoopin
on the device, IP source
uard
enerates IP
source guard entries based on the DHCPv6 snooping entries, which are usually generated first, to filter
packets on a port.
Setting the maximum number of IPv6 source guard entries
The maximum number of IPv6 source guard entries is used to limit the total number of static and dynamic
IPv6 source guard entries on a port. When the number of IPv6 binding entries on a port reaches the
maximum, the port does not allow new IPv6 binding entries any more.
Follow these steps to configure the maximum number of IPv6 binding entries allowed on a port:
To do… Use the command… Remarks
Enter system view system-view —
Enter Layer 2 Ethernet interface
view
interface interface-type
interface-number
—
Configure the maximum number of
IPv6 binding entries allowed on the
port
ip check source ipv6 max-entries
number
Optional
256 by default.
NOTE:
If the maximum number of IPv6 bindin
entries to be confi
ured is smaller than the number of existin
IPv6
bindin
entries on the port, the maximum number can be confi
ured successfully and the existin
entries
ill be not be affected. New IPv6 bindin
entries, however, cannot be added more unless the number of
IPv6 binding entries on the port drops below the configured maximum.
Displaying and maintaining IP source guard
For IPv4:
To do… Use the command… Remarks
Display static IPv4 source guard
entries
display user-bind [ interface interface-type
interface-number | ip-address ip-address |
mac-address mac-address ] [ | { begin |
exclude | include } regular-expression ]
Available in any view
Display IPv4 source guard entries
display ip check source [ interface
interface-type interface-number |
ip-address ip-address | mac-address
mac-address ] [ slot slot-number ] [ | { begin
| exclude | include } regular-expression ]
Available in any view
For IPv6: