Administrator Guide

IPv6 Routing 1421
ipv6 route 2001::/16 null 254
ipv6 route 2002::/16 null 254
These address ranges are reserved and not reachable in the Internet. If for
some reason you have local networks in this range, a more specific route
will have precedence.
Another use for the Reject route is to prevent internal hosts from
communication with specific addresses or ranges of addresses. The effect is
the same as an outgoing access-list with a “deny” statement. A route is
generally more efficient than an access-list that performs the same function.
If you need more fine-grained filtering, such as protocols or port numbers, use
the access-list instead.
IPv6 Router Advertisement Guard
Dell Networking N-Series switches support IPv6 Router Advertisement Guard
(RA-Guard) to protect against attacks via rogue Router Advertisements in
accordance with RFC 6105. Dell Networking RA-Guard supports Stateless
RA-Guard, where the administrator can configure the interface to allow
received router advertisements and router redirect message to be
processed/forwarded or dropped.
By default, RA-Guard is not enabled on any interfaces. RA-Guard is
enabled/disabled on physical interfaces or port-channels. RA-Guard does not
require IPv6 routing to be enabled. This allows VLANs to span interfaces
connected to routers and hosts, while allowing configuration such that router
advertisements or redirect messages received from connected hosts are
dropped (L2 configuration). L3 configuration of RA-Guard on IPv6 routing
interfaces is also supported.
Dell Networking supports a single unnamed RA-Guard policy that blocks all
incoming IPv6 router advertisements and IPv6 router redirect messages. The
single unnamed policy is pre-configured and may not be renamed or removed.
The following example configures the unnamed RA-Guard policy to drop all
RA advertisements and router redirect messages on host connected routed
interface Gi1/0/1. In the example, routed VLAN 10 is isolated to physical
interface Gi1/0/1 connected to a host. IPv6 routing is enabled on VLAN 10
and IPv6 unicast routing is enabled globally. Interface gi1/0/1 is placed into