197
Ste
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
N/A
3. Enable DHCPv6-REQUEST
check.
ipv6 dhcp snooping check
request-message
By default, DHCPv6-REQUEST check is
disabled.
You can enable the function only on Layer
2 Ethernet interfaces and Layer 2
aggregate interfaces.
Configuring DHCPv6 packet rate limit
This DHCPv6 packet rate limit feature discards exceeding DHCPv6 packets to prevent attacks that send
large numbers of DHCPv6 packets.
To configure DHCPv6 packet rate limit:
Ste
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
N/A
3. Specify the maximum
rate at which an
interface can receive
DHCPv6 packets.
ipv6 dhcp snooping
rate-limit rate
By default, incoming DHCPv6 packets on an
interface are not rate limited.
You can configure this command only on Layer
2 Ethernet interfaces and Layer 2 aggregate
interfaces.
If you specify the maximum rate on a Layer 2
Ethernet interface that is a member port of a
Layer 2 aggregate interface, the Layer 2
Ethernet interface uses the DHCP packet
maximum rate configured on the Layer 2
aggregate interface. If the Layer 2 Ethernet
interface leaves the aggregation group, it uses
its own DHCP packet maximum rate.
Displaying and maintaining DHCPv6 snooping
Execute display commands in any view, and reset commands in user view.
Task Command
Display information about trusted ports.
display ipv6 dhcp snooping trust
Display DHCPv6 snooping entries.
display ipv6 dhcp snooping binding [ address
ipv6-address [ vlan vlan-id ] ]