Quick Reference Guide
DHCPv6 Snooping Commands 985
Syntax
ipv6 verify binding
mac-address
vlan
vlan-id
ip-address
interface
interface id
no ipv6 verify binding
mac-address
vlan
vlan-id
ip-address
interface
interface
id
•
mac-address
—A valid mac address in standard format.
•
vlan-id
—A configured VLAN id. (Range 1-4093.
•
ip-address
—A valid IPv6 address.
•
interface-id
—A valid interface ID in short or long format.
Default Configuration
By default, no static IP Source Guard entries are configured.
Command Modes
Global Configuration mode
User Guidelines
Traffic is filtered based upon the source IPv6 address and VLAN. Use the port
security command in interface mode to optionally add MAC address filtering
in addition to source IPv6 address filtering. If port security is enabled, the
filtering is based upon IPv6 address, MAC address and VLAN.
ipv6 verify source
Use the ipv6 verify source command to configure an interface to filter (drop)
incoming traffic from sources that are not present in the DHCP binding
database. Use the no form of the command to enable unverified traffic to
flow over the interfaces.
Syntax
ipv6 verify source [port-security]
no ipv6 verify source
•
port-security
— Enables filtering based upon source IP address, VLAN and
MAC address.
2CSNXXX_SWUM200.book Page 985 Tuesday, December 10, 2013 1:22 PM










