Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The set ipipv6-source-guard enable command can be used to enable or disable IP IPv6 source guard function based on ingress interface and VLAN of the packet.

The delete ipipv6-source-guard enable command deletes the configuration.

Command Syntax

set ipipv6-source-guard interface <interface-name> vlan <vlan-id> enable <true | false>

delete ipipv6-source-guard interface <interface-name> vlan <vlan-id> enable

...

Parameter

Description

interface <interface-name>

Specifies an ingress interface name. The value is a physical port or a LAG port, such as ge-1/1/1, te-1/1/2, ae1.

Note:

IP IPv6 source guard be enabled on a physical interface or a Link Aggregation Group (LAG) interface but cannot be enabled on the member interfaces of a LAG.

vlan <vlan-id>

Specifies a VLAN ID. The value is an integer that ranges from 1 to 4094.

  • For IP IPv6 source guard static binding table, specifies the VLAN ID manually configured in IP IPv6 source guard static binding table.

  • For IP IPv6 source guard dynamic binding table, specifies the VLAN ID enabled DHCP DHCPv6 snooping.

enable <true | false>

Enable or disable IP IPv6 source guard function. The value could be true or false.

  • true: Enable IP IPv6 source guard function.

  • false: Disable IP IPv6 source guard function.

By default, IP IPv6 source guard function is disabled.

Usage Guidelines

IP IPv6 source guard should be enabled based on specific interfaces and VLANs. When IP IPv6 source guard is enabled based on a specific interface and VLAN, all packets from that interface and VLAN will be dropped except those that match entries in the IP IPv6 source guard binding table.

Packets received from interfaces or VLANs that do not have IP IPv6 source guard enabled will not be checked by the IP IPv6 source guard module and will be processed as normal.

Example

  • Enable IP IPv6 source guard on interface ge-1/1/3 and VLAN 20.

Code Block
admin@PICOS# set ipipv6-source-guard interface ge-1/1/3 vlan 20 enable true
admin@PICOS# commit