R21xx-HP FlexFabric 11900 Security Configuration Guide

117
Ste
p
Command
Remarks
3. Enable the IPv6 source guard
function.
ipv6 verify source ip-address
[ mac-address ]
By default, the function is disabled
on an interface.
If you configure this command on
an interface multiple times, the
most recent configuration takes
effect.
Configuring a static IPv6 source guard binding entry on an
interface
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
These types of interfaces are supported:
Layer 2 Ethernet interface, Layer 3 Ethernet
port, and VLAN interface.
3. Configure a static IPv6
binding entry.
ipv6 source binding ip-address
ipv6-address [ mac-address
mac-address ] [ vlan vlan-id ]
By default, no static IPv6 binding entry is
configured on an interface.
The option vlan vlan-id is only available in
Layer 2 Ethernet interface view.
NOTE:
You cannot configure the same static binding entry on one interface multiple times, but you can confi
g
ure
the same static binding entry on different interfaces.
Displaying and maintaining IP source guard
Execute display commands in any view and reset commands in user view.
For IPv4 source guard:
Task Command
Display IPv4 binding
entries (in standalone
mode).
display ip source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcp-relay | dhcp-server | dhcp-snooping ] ] [ ip-address ip-address ]
[ mac-address mac-address ] [ vlan vlan-id ] [ interface interface-type
interface-number ] [ slot slot-number ]
Display IPv4 binding
entries (in IRF mode).
display ip source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcp-relay | dhcp-server | dhcp-snooping ] [ ip-address ip-address ]
[ mac-address mac-address ] [ vlan vlan-id ] [ interface interface-type
interface-number ] [ chassis chassis-number slot slot-number ]
Clear IPv4 binding entries.
reset ip source binding [ static [ ip-address ip-address ] | [ vpn-instance
vpn-instance-name ] [ { dhcp-relay | dhcp-server | dhcp-snooping } [ ip-address
ip-address ] ] ]
For IPv6 source guard: