R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
301
mac-address: Filters packets by source MAC addresses. With this keyword specified, the IP source guard
function on the interface filters a received packet by using source MAC addresses of the IPv6 source
guard binding entries. If a match is found, the interface forwards the packet. Otherwise, the interface
discards the packet.
Usage guidelines
After you enable IPv6 source guard on an interface, IP source guard can perform the following
operations:
Generate dynamic IPv6 source guard binding entries based on DHCPv6 snooping entries.
Use static and dynamic IPv6 source guard binding entries to filter IPv6 packets received on the
interface.
If a packet matches an IPv6 source guard binding entry, IP source guard forwards the packet. Otherwise,
it drops the packet.
You cannot enable dynamic IPv6 source guard on a service loopback interface.
Examples
# Enable IPv6 source guard on Layer 2 Ethernet interface Ten-GigabitEthernet 1/0/1 to filter packets
received on the port based on the source IPv6 and MAC addresses.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] ipv6 verify source ip-address mac-address
Related commands
display ipv6 source binding