User's Manual

Table Of Contents
Users Manual of SGS-5240 Series Managed Switch
240
4.7.14 IPv6 Source Guard
4.7.14.1 Interface Configuration
Security > IPv6 Source Guard > Interface Configuration page is used to filter inbound traffic based on the source IPv6 address
stored in the binding table.
Port
Port identifier.
Filter TypeConfigures the switch to filter inbound traffic based on the following options. (Default: Disabled)
DisabledDisables IPv6 source guard filtering on the port.
Source IP Enables traffic filtering based on IPv6 global unicast source IPv6 addresses stored in the binding table.
Max Binding Entry
The maximum number of entries that can be bound to an interface. (Range: 1-5; Default: 5)
This parameter sets the maximum number of IPv6 global unicast source IPv6 address entries that can be mapped
to an interface in the binding table, including both dynamic entries discovered by ND snooping, DHCPv6 snooping .
IPv6 source guard maximum bindings must be set to a value higher than DHCPv6 snooping maximum bindings and
ND snooping maximum bindings.
If IPv6 source guard, ND snooping, and DHCPv6 snooping are enabled on a port, the dynamic bindings used by ND
snooping, DHCPv6 snooping, and IPv6 source guard static bindings cannot exceed the maximum allowed bindings
set by this parameter. In other words, no new entries will be added to the IPv6 source guard binding table.
If IPv6 source guard is enabled on a port, and the maximum number of allowed bindings is changed to a lower value,
precedence is given to deleting entries learned through DHCPv6 snooping, ND snooping, and then manually
configured IPv6 source guard static bindings, until the number of entries in the binding table reaches the newly
configured maximum number of allowed bindings.