Manual
+7(495) 797-3311 www.qtech.ru 
Москва, Новозаводская ул., 18, стр. 1 
366 
debug ipv6 security-ra 
no debug ipv6 security-ra 
Enable the debug information of IPv6 security 
RA module, the no operation of this command 
will disable the output of debug information of 
IPv6 security RA. 
show ipv6 security-ra [interface <interface-
list>] 
Display the distrust port and whether globally 
security RA is enabled. 
47.3 IPv6 Security RA Typical Examples 
IPv6 Security RA sketch map 
Instructions: if the illegal user in the graph advertises RA, the normal user will receive the RA, 
set  the  default  router  as  the  vicious  IPv6  host  user  and  change  its  own  address.  This  will 
cause the normal user to not be able to connect the network. We want to set security RA on 
the 1/2 port of the switch, so that the RA from the illegal user will not affect the normal user. 
Switch configuration task sequence: 
Switch#config 
Switch(config)#ipv6 security-ra enable 
Switch(Config-If-Ethernet1/2)# ipv6 security-ra enable 
47.4 IPv6 Security RA Troubleshooting Help 
The function of IPv6 security RA is quite simple, if the function does not meet the expectation 
after configuring IPv6 security RA: 
   Check if the switch is correctly configured. 
Illegal User 
PC 
User 
Other IPv6 network 
RA 
Ethernet1/1 
Ethernet1/3 
Ethernet1/2 
RA 
X 










