HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 278
ND attack defense configuration commands, ipv6 nd mac-check enable
View all HP 6125G manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 278 highlights
ND attack defense configuration commands ipv6 nd mac-check enable Syntax ipv6 nd mac-check enable View undo ipv6 nd mac-check enable System view Default level 2: System level Parameters None Description Use ipv6 nd mac-check enable to enable source MAC consistency check for ND packets. Use undo ipv6 nd mac-check enable to disable source MAC consistency check for ND packets. By default, source MAC consistency check is disabled for ND packets. In a typical forged ND packet, the Ethernet frame header conveys a source MAC address different than the source link layer address option. To filter out these invalid ND packets, use the source MAC consistency check function to check ND packets for MAC address inconsistency. If VRRP is used, disable source MAC consistency check for ND packets to prevent incorrect dropping of packets. With VRRP, the NA message always conveys a MAC address different than the source link layer address option. Examples # Enable source MAC consistency check for ND packets. system-view [Sysname] ipv6 nd mac-check enable 269