ipv6 neighbor inspection vlan

Configures and enables Neighbor Discovery (ND) inspection on a VLAN, or a range of VLANs, to inspect the IPv6 packets from untrusted ports.
Syntax
ipv6 neighbor inspection vlan vlan-id [ to vlan-id … ]
no ipv6 neighbor inspection vlan vlan-id [ to vlan-id … ]
Command Default

IPv6 ND inspection is not enabled.

Parameters
vlan-id
Configures the ID of the VLAN.
to vlan-id
Specifies a range of VLANs.
Modes

Global configuration mode

VRF configuration mode

Usage Guidelines

When you configure this command, IPv6 packets from untrusted ports on the VLAN undergo ND inspection.

All VLANs included in the range when using the to keyword must be valid VLANs. Otherwise an error will occur.

The no form of the command disables ND inspection.

Examples

The following example enables ND inspection on VLAN 10.

device# configure terminal
device(config)# ipv6 neighbor inspection vlan 10

The following example enables ND inspection on VLAN 10 of VRF 3.

device# configure terminal
device(config)# vrf 3
device(config-vrf-3)# ipv6 neighbor inspection vlan 10

The following example configures VLANs 100 through 150, VLAN 160, and VLANs 170 through 200 and enables ND inspection on all of the configured VLANs.

device# configure terminal
device(config)# vlan 100 to 150
device(config-mvlan-100-150)# exit
device(config)# vlan 150 to 200
device(config-mvlan-150-200)# exit
device(config)# ipv6 neighbor inspection vlan 100 to 150 160 170 to 200
History
Release version Command history
08.0.20 This command was introduced.
08.0.80 The to keyword was added to enable ND inspection on a range of VLANs by using a single command.