IPv6 infrastructure security features

4.2.c i RA Guard

General information on “IPv6 IS RA Guard”:

RA guard configuration steps:

  1. Define RA guard policy
  2. Apply RA guard policy to an interface

“IPv6 IS RA Guard” CLI configuration commands:

## Defining a RA guard policy
Switch(config)# ipv6 nd raguard policy [NAME]
Switch(config-nd-raguard)# device-role <role>

## Applying a RA guard policy to an interface
Switch(config)# interface <if>
Switch(config-if)# ipv6 nd raguard attach-policy [NAME]

“IPv6 IS RA Guard” CLI show commands:

## Showing interfaces configured with RA guard
Switch# show ipv6 nd raguard policy [NAME]

4.2.c ii DHCP Guard

General information on “IPv6 IS DHCP Guard”:

DHCP guard configuration steps:

  1. Define DHCP guard policy
  2. Apply DHCP guard policy to an interface

“IPv6 IS DHCP Guard” CLI configuration commands:

## Defining a DHCP guard policy
Switch(config)# ipv6 dhcp guard policy [NAME]
Switch(config-nd-raguard)# device-role <role>

## Applying a DHCP guard policy to an interface
Switch(config)# interface <if>
Switch(config-if)# ipv6 dhcp guard attach-policy [NAME]

“IPv6 IS DHCP Guard” CLI show commands:

## Showing interfaces configured with DHCP guard
Switch# show ipv6 dhcp guard policy

4.2.c iii Binding table

General information on “IPv6 IS Binding table”:

“IPv6 IS Binding table” CLI configuration commands:

## Configuring a static IPv6 binding table entry
Switch(config)# ipv6 neighbor binding vlan <vlan-id> <ipv6-addr> interface <if> <mac-addr>

“IPv6 IS Binding table” CLI show commands:

## Showing the IPv6 binding table
Switch# show ipv6 neighbors binding

4.2.c iv Device tracking

General information on “IPv6 IS Device tracking”:

“IPv6 IS Device tracking” CLI configuration commands:

## Enabling Device tracking globally
Switch(config)# ipv6 neighbor tracking

4.2.c v ND inspection/snooping

General information on “IPv6 IS ND inspection/snooping”:

“IPv6 IS ND inspection/snooping” CLI configuration commands:

## Defining a ND inspection/snooping policy
Switch(config)# ipv6 nd inspection policy [NAME]

## Applying a ND inspection/snooping policy to an interface
Switch(config)# interface <if>
Switch(config-if)# ipv6 nd inspection attach-policy [NAME]

“IPv6 IS ND inspection/snooping” CLI show commands:

## Showing interfaces configured with NS inspection/snooping
Switch# show ipv6 nd inspection policy [NAME]

4.2.c vi Source Guard

General information on “IPv6 IS Source Guard”:

“IPv6 IS Source Guard” CLI configuration commands:

## Defining a Source Guard policy
Switch(config)# ipv6 source-guard policy [NAME]
Switch(config-nd-raguard)# deny global-autoconf
Switch(config-nd-raguard)# permit link-local

## Applying a Source Guard policy to an interface
Switch(config)# interface <if>
Switch(config-if)# ipv6 source-guard attach-policy [NAME]

“IPv6 IS Source Guard” CLI show commands:

## Showing interfaces configured with Source Guard
Switch# show ipv6 source-guard policy [NAME]