Web Management Guide-R01

Table Of Contents
Chapter 12
| Security Measures
ND Snooping
– 371 –
Configuring Ports for
ND Snooping
Use the Security > ND Snooping > Configure Interface page to configure ports as
trusted interfaces from which prefix information in RA messages can be added to
the prefix table, or NS messages can be forwarded without validation.
Usage Guidelines
In general, interfaces facing toward to the network core, or toward routers
supporting the Network Discovery protocol, are configured as trusted
interfaces.
RA messages received from a trusted interface are added to the prefix table and
forwarded toward their destination.
NS messages received from a trusted interface are forwarded toward their
destination. Nothing is added to the dynamic user binding table.
Parameters
These parameters are displayed:
Trust Status – Enables or disables a port as trusted. (Default: Disabled)
Max Binding – The maximum number of address entries in the dynamic user
binding table which can be bound to a port. (Range: 1-5; Default: 5)
Web Interface
To configure ND Snooping on a port interface:
1. Click Security, ND Snooping, Configure Interface.
2. Set the required ports’ Trust Status to enabled.
3. Click Apply.
Figure 232: ND Snooping Interface Configuration