483
more information about the information center, see Network Management and Monitoring
Configuration Guide.
To enable the RA guard logging feature:
Step Command Remarks
1. Enter system view.
system-view
N/A
2. Enable the RA guard logging
feature.
ipv6 nd raguard log enable
By default, the RA guard logging
feature is disabled.
Displaying and maintaining RA guard
Execute display commands in any view and reset commands in user view.
Task Command
Display the RA guard policy configuration.
display ipv6 nd raguard policy
[ policy-name ]
Display RA guard statistics.
display ipv6 nd raguard statistics
[
interface
interface-type
interface-number ]
Clear RA guard statistics.
reset ipv6 nd raguard statistics
[
interface
interface-type
interface-number ]
RA guard configuration example
Network requirements
As shown in Figure 138, Ten-GigabitEthernet 1/0/1, Ten-GigabitEthernet 1/0/2, and
Ten-GigabitEthernet 1/0/3 of Device B are in VLAN 10.
Configure RA guard on Device B to filter forged and unwanted RA messages.
• Configure an RA policy in VLAN 10 for Ten-GigabitEthernet 1/0/2 to filter all RA messages
received from the unknown device.
• Specify host as the role of the host. All RA messages received on Ten-GigabitEthernet 1/0/1
are dropped.
• Specify router as the role of the Device A. All RA messages received on Ten-GigabitEthernet
1/0/3 are forwarded.
Figure 138 Network diagram