raguard
Interface configuration mode
The
no form of this command removes the current trusted or untrusted configuration.
A trusted RA guard port forwards all the receive RA packets without inspecting. An untrusted port inspects the received RAs against the RA guard policy’s whitelist, prefix list and preference maximum settings before forwarding the RA packets. If an RA guard policy is not configured on an untrusted or host port, all the RA packets are forwarded.
The following example configures an interface as a trusted RA guard port:
device(config)# interface ethernet1/1/1 device(config-int-e1000-1/1/1)# raguard trust
The following example configures an interface as an untrusted RA guard port:
device(config)# interface ethernet1/2/1 device(config-int-e1000-1/2/1)# raguard untrust