Deployment Guide

Table Of Contents
2. Enable the IPv6 RA guard.
CONFIGURATION mode
ipv6 nd ra-guard enable
3. Create the policy.
POLICY LIST CONFIGURATION mode
ipv6 nd ra-guard policy policy-name
4. Define the role of the device attached to the port.
POLICY LIST CONFIGURATION mode
device-role {host | router}
Use the keyword host to set the device role as host.
Use the keyword router to set the device role as router.
5. Set the hop count limit.
POLICY LIST CONFIGURATION mode
hop-limit {maximum | minimum limit}
The hop limit range is from 0 to 254.
6. Set the managed address configuration flag.
POLICY LIST CONFIGURATION mode
managed-config-flag {on | off}
7. Enable verification of the sender IPv6 address in inspected messages from the authorized device source access list.
POLICY LIST CONFIGURATION mode
match ra{ipv6-access-list name | ipv6-prefix-list name | mac-access-list name}
8. Enable verification of the advertised other configuration parameter.
POLICY LIST CONFIGURATION mode
other-config-flag {on | off}
9. Enable verification of the advertised default router preference value. The preference value must be less than or equal to the
specified limit.
POLICY LIST CONFIGURATION mode
router-preference maximum {high | low | medium}
10. Set the router lifetime.
POLICY LIST CONFIGURATION mode
routerlifetime value
The router lifetime range is from 0 to 9,000 seconds.
11. Apply the policy to trusted ports.
POLICY LIST CONFIGURATION mode
trusted-port
12. Set the maximum transmission unit (MTU) value.
POLICY LIST CONFIGURATION mode
mtu value
13. Set the advertised reachability time.
POLICY LIST CONFIGURATION mode
reachabletime value
The reachability time range is from 0 to 3,600,000 milliseconds.
14. Set the advertised retransmission time.
POLICY LIST CONFIGURATION mode
retranstimer value
The retransmission time range is from 100 to 4,294,967,295 milliseconds.
15. Display the configurations applied on the RA guard policy mode.
POLICY LIST CONFIGURATION mode
432
IPv6 Routing