HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 179

Static IPv6 source guard configuration example, Network requirements, Configuration procedure,

Page 179 highlights

Static IPv6 source guard configuration example Network requirements As shown in Figure 60, the host is connected to port Ten-GigabitEthernet 1/1/5 of the switch. Configure a static IPv6 source guard binding entry for Ten-GigabitEthernet 1/1/5 of the switch to allow only IPv6 packets from the host to pass. Figure 60 Network diagram Configuration procedure # Enable IPv6 source guard on port Ten-GigabitEthernet 1/1/5. system-view [Switch] interface ten-gigabitEthernet 1/1/5 [Switch-Ten-GigabitEthernet1/1/5] ipv6 verify source ip-address mac-address # On port Ten-GigabitEthernet 1/1/5, configure a static IPv6 source guard binding entry to allow only IPv6 packets with the source IPv6 address of 2001::1 and the source MAC address of 00-01-02-02-02-02 to pass. [Switch-Ten-GigabitEthernet1/1/5] ipv6 source binding ip-address 2001::1 mac-address 0001-0202-0202 [Switch-Ten-GigabitEthernet1/1/5] quit Verifying the configuration # Display static IPv6 source guard binding entries on the switch. The output shows that a static binding entry is configured successfully. [Switch] display ipv6 source binding static Total entries found: 1 IPv6 Address MAC Address Interface VLAN Type 2001::1 0001-0202-0202 XGE1/1/5 N/A Static 170

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

170
Static IPv6 source guard configuration example
Network requirements
As shown in
Figure 60
, the host is connected to port Ten-GigabitEthernet 1/1/5 of the switch.
Configure a static IPv6 source guard binding entry for Ten-GigabitEthernet 1/1/5 of the switch to allow
only IPv6 packets from the host to pass.
Figure 60
Network diagram
Configuration procedure
# Enable IPv6 source guard on port Ten-GigabitEthernet 1/1/5.
<Switch> system-view
[Switch] interface ten-gigabitEthernet 1/1/5
[Switch-Ten-GigabitEthernet1/1/5] ipv6 verify source ip-address mac-address
# On port Ten-GigabitEthernet 1/1/5, configure a static IPv6 source guard binding entry to allow only
IPv6 packets with the source IPv6 address of 2001::1 and the source MAC address of 00-01-02-02-02-02
to pass.
[Switch-Ten-GigabitEthernet1/1/5] ipv6 source binding ip-address 2001::1 mac-address
0001-0202-0202
[Switch-Ten-GigabitEthernet1/1/5] quit
Verifying the configuration
# Display static IPv6 source guard binding entries on the switch. The output shows that a static binding
entry is configured successfully.
[Switch] display ipv6 source binding static
Total entries found: 1
IPv6 Address
MAC Address
Interface
VLAN Type
2001::1
0001-0202-0202 XGE1/1/5
N/A
Static