Web Management Guide-R02

Table Of Contents
Chapter 12
| Security Measures
ND Snooping
– 382 –
ND Snooping VLAN
Configuration
Use the Security > ND Snooping > Configure VLAN (Add) page to enable ND
Snooping on a specified VLAN or range of VLANs.
Parameters
These parameters are displayed:
VLAN ID - A specific VLAN ID or a consecutive range of VLANs. (Range: 1-4094)
Web Interface
To configure ND Snooping on a VLAN:
1. Click Security, ND Snooping, Configure VLAN.
2. Specify a VLAN ID or range of VLAN IDs.
3. Click Apply.
Figure 239: ND Snooping VLAN Configuration
Configuring Ports for
ND Snooping
Use the Security > ND Snooping > Configure Interface page to configure ports as
trusted interfaces from which prefix information in RA messages can be added to
the prefix table, or NS messages can be forwarded without validation.
Usage Guidelines
In general, interfaces facing toward to the network core, or toward routers
supporting the Network Discovery protocol, are configured as trusted
interfaces.
RA messages received from a trusted interface are added to the prefix table and
forwarded toward their destination.
NS messages received from a trusted interface are forwarded toward their
destination. Nothing is added to the dynamic user binding table.