Users Guide

IPv6 Routing 1427
ipv6 route 2001::/16 null 254
ipv6 route 2002::/16 null 254
These address ranges are reserved and not reachable in the Internet. If for
some reason you have local networks in this range, a more specific route
will have precedence.
Another use for the Reject route is to prevent internal hosts from
communication with specific addresses or ranges of addresses. The effect is
the same as an outgoing access-list with a “deny” statement. A route is
generally more efficient than an access-list that performs the same function.
If you need more fine-grained filtering, such as protocols or port numbers, use
the access-list instead.
IPv6 Router Advertisement Guard
Dell EMC Networking N-Series switches support IPv6 Router Advertisement
Guard (RA-Guard) to protect against attacks via rogue Router
Advertisements in accordance with RFC 6105. Dell EMC Networking RA-
Guard supports Stateless RA-Guard, where the administrator can configure
the interface to allow received router advertisements and router redirect
message to be processed/forwarded or dropped.
By default, RA-Guard is not enabled on any interfaces. RA-Guard is
enabled/disabled on physical interfaces or port-channels. RA-Guard does not
require IPv6 routing to be enabled. This allows VLANs to span interfaces
connected to routers and hosts, while allowing configuration such that router
advertisements or redirect messages received from connected hosts are
dropped (L2 configuration). L3 configuration of RA-Guard on IPv6 routing
interfaces is also supported.
Dell EMC Networking supports a single unnamed RA-Guard policy that
blocks all incoming IPv6 router advertisements and IPv6 router redirect
messages. The single unnamed policy is preconfigured and may not be
renamed or removed.
The following example configures the unnamed RA-Guard policy to drop all
RA advertisements and router redirect messages on host connected routed
interface Gi1/0/1. In the example, routed VLAN 10 is isolated to physical
interface Gi1/0/1 connected to a host. IPv6 routing is enabled on VLAN 10
and IPv6 unicast routing is enabled globally. Interface gi1/0/1 is placed into