HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 173

Configuring the IPv6 source guard function, Enabling IPv6 source guard on an interface

Page 173 highlights

NOTE: • You cannot configure the same static binding entry on one interface, but you can configure the same static binding entry on different interfaces. • For packet filtering on an interface, IP source guard ignores the VLAN information (if specified) in static IPv4 source guard binding entries. To cooperate with ARP detection, you must specify the VLAN where ARP detection is configured in static IPv4 source guard binding entries. Otherwise, ARP packets will be discarded because they cannot match any static IPv4 entry. For more information about the ARP detection function, see Security Configuration Guide. Configuring the IPv6 source guard function You cannot configure the IPv6 source guard function on a service loopback interface. If IPv6 source guard is enabled on an interface, you cannot assign the interface to a service loopback group. Enabling IPv6 source guard on an interface You must first enable the IPv6 source guard function on an interface before the interface can use static IPv6 binding entries to filter packets. For information about how to configure a static IPv6 binding entry, see "Configuring a static IPv6 source guard binding entry on an interface." To enable the IPv6 source guard function on an interface: Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number 3. Enable the IPv6 source guard ipv6 verify source ip-address function. [ mac-address ] Remarks N/A These types of interfaces are supported: Ethernet port and VLAN interface. By default, the function is disabled on an interface. Configuring a static IPv6 source guard binding entry on an interface Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number Remarks N/A These types of interfaces are supported: Ethernet interface and VLAN interface. 164

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

164
NOTE:
You cannot configure the same static binding entry on one interface, but you can configure the same
static binding entry on different interfaces.
For packet filtering on an interface, IP source guard ignores the VLAN information (if specified) in static
IPv4 source guard binding entries. To cooperate with ARP detection, you must specify the VLAN where
ARP detection is configured in static IPv4 source guard binding entries. Otherwise, ARP packets will be
discarded because they cannot match any static IPv4 entry. For more information about the ARP
detection function, see
Security Configuration Guide
.
Configuring the IPv6 source guard function
You cannot configure the IPv6 source guard function on a service loopback interface. If IPv6 source
guard is enabled on an interface, you cannot assign the interface to a service loopback group.
Enabling IPv6 source guard on an interface
You must first enable the IPv6 source guard function on an interface before the interface can use static
IPv6 binding entries to filter packets. For information about how to configure a static IPv6 binding entry,
see "
Configuring a static IPv6 source guard binding entry on an interface
."
To enable the IPv6 source guard function on an interface:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
These types of interfaces are
supported: Ethernet port and VLAN
interface.
3.
Enable the IPv6 source guard
function.
ipv6 verify source ip-address
[
mac-address
]
By default, the function is disabled
on an interface.
Configuring a static IPv6 source guard binding entry on an
interface
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
These types of interfaces are supported:
Ethernet interface and VLAN interface.