452 
Configuration procedure 
# Enable IPv6SG on Ten-GigabitEthernet 1/0/1. 
<Device> system-view 
[Device] interface ten-gigabitethernet 1/0/1 
[Device-Ten-GigabitEthernet1/0/1] ipv6 verify source ip-address mac-address 
# On Ten-GigabitEthernet 1/0/1, configure a static IPv6SG binding for the host. 
[Device-Ten-GigabitEthernet1/0/1] ipv6 source binding ip-address 2001::1 mac-address 
0001-0202-0202 
[Device-Ten-GigabitEthernet1/0/1] quit 
Verifying the configuration 
# Verify that the static IPv6SG binding is configured successfully on the device. 
[Device] display ipv6 source binding static 
Total entries found: 1 
IPv6 Address         MAC Address    Interface               VLAN Type 
2001::1              0001-0202-0202 XGE1/0/1                N/A  Static 
Dynamic IPv6SG using DHCPv6 snooping configuration 
example 
Network requirements 
As shown in Figure 126, the host (the DHCPv6 client) obtains an IP address from the DHCPv6 server. 
Perform the following tasks: 
•  Enable DHCPv6 snooping on the device to make sure the DHCPv6 client obtains an IPv6 
address from the authorized DHCPv6 server. To generate a DHCPv6 snooping entry for the 
DHCPv6 client, enable recording of client information in DHCPv6 snooping entries. 
•  Enable dynamic IPv6SG on Ten-GigabitEthernet 1/0/1 to filter incoming packets by using the 
IPv6SG bindings generated based on DHCPv6 snooping entries. Only packets from the 
DHCPv6 client are allowed to pass. 
Figure 126 Network diagram 
 
 
Configuration procedure 
1.  Configure DHCPv6 snooping: 
# Enable DHCPv6 snooping globally. 
<Device> system-view 
[Device] ipv6 dhcp snooping enable 
# Configure Ten-GigabitEthernet 1/0/2 as a trusted interface. 
[Device] interface ten-gigabitethernet 1/0/2 
[Device-Ten-GigabitEthernet1/0/2] ipv6 dhcp snooping trust 
[Device-Ten-GigabitEthernet1/0/2] quit 
2.  Enable IPv6SG: 
# Enable IPv6SG on Ten-GigabitEthernet 1/0/1 and verify the source IP address and MAC 
address for dynamic IPv6SG.