SGS-6340 Series User Manual

Table Of Contents
3. Display
and debug the related information of IPv6 security RA
Command Explanation
Admin Mode
debug ipv6 security-ra
no debug ipv6 security-ra
Enable the debug information of IPv6
security RA module, the no operation of
this command will disable the output of
debug information of IPv6 security RA.
show ipv6 security-ra [interface
<interface-list>]
Display the untrusted port and whether
globally security RA is enabled.
49.3 IPv6 Security RA Typical Examples
Other IPv6 network
PC User
RA Ethernet1/1
Eth
ernet1/2
RA
X
Ethernet1/3
Illegal User
Figure 49-1:
IPv6 Security RA sketch map
Instructions: if the illegal user in the graph advertises RA, the normal user will receive the RA,
set the default router as the vicious IPv6 host user and change its own address. This will cause
the normal user to not be able to connect the network. We want to set security RA on the 1/2
port of the switch, so that the RA from the illegal user will not affect the normal user.
Switch configuration task sequence:
Switch#config
Switch(config)#ipv6 security-ra enable
Switch(Config-If-Ethernet1/2)# ipv6 security-ra enable
49-122