show ipv6 neighbor inspection

Displays the status of the neighbor discovery (ND) inspection configuration, details of the VLANs on which ND inspection is enabled, ND static entries, and ND inspection statistics.
Syntax
show ipv6 neighbor[vrfvrf-name]inspection[static-entry|statistics|vlanvlan-number]
Parameters
static-entry
Specifies the manually configured static ND inspection entries that are used to validate the packets received on untrusted ports.
statistics
Specifies the total number of neighbor discovery messages received and the number of packets discarded after ND inspection.
vlan
Specifies the VLANs on which ND inspection is enabled.
vlan-number
Specifies the ID of the configured VLAN.
vrf
Specifies the VRF instance.
vrf-name
Specifies the ID of the VRF instance.
inspection
Specifies that the neighbor discovery messages are verified against the static ND inspection entries or dynamically learned DHCPv6 snoop entries.
Modes

Privileged EXEC mode

Global configuration mode

VRF configuration mode

The show ipv6 neighbor inspection command displays the following information.

Output field Description
VLAN The list of VLANs on which ND inspection is enabled.
IPv6 Address The IPv6 addresses of the hosts that are added as static ND inspection entries.
LinkLayer-Addr The MAC addresses of the hosts that are added as static ND inspection entries.
Total number of ND Solicit received The total number of neighbor solicitation messages received.
Total number of ND Advert received The total number of neighbor advertisement messages received.
Total number of Router Solicit received The total number of router solicitation messages received.
Total number of ND dropped The total number of neighbor discovery messages that are discarded because of the IP-to-MAC address binding discrepancy.
IPv6 Neighbor inspection VLAN vlan-number The status of ND inspection on a VLAN.
Untrusted Ports The interfaces or member ports on which trust mode is not enabled.
Trusted Ports The interfaces or member ports on which trust mode is enabled.
Examples

The following example shows the output of the show ipv6 neighbor inspection command.

device(config)# show ipv6 neighbor inspection
IPv6 Neighbor inspection enabled on 2 VLAN(s):
        VLAN: 2
        VLAN: 3

The following example shows the output of the ND inspection configuration details for a VRF.

device(config-vrf-3)# show ipv6 neighbor vrf 3 inspection
IPv6 Neighbor inspection enabled on 2 VLAN(s):
        VLAN: 2
        VLAN: 3

The following example shows the output of the show ipv6 neighbor inspectionstatic-entry command.

device(config)# show ipv6 neighbor inspection static-entry
 Total number of ND Inspect entries: 3
 IPv6 Address                            LinkLayer-Addr      
 2001::1                                 0000.0000.1234      
 2001::3                                 0000.1234.4567      
 2001::2                                 0000.0000.4567

The following example shows the ND static entries of a VRF.

device(config-vrf-3)# show ipv6 neighbor vrf 3 inspection static-entry
 Total number of ND Inspect entries: 1
 IPv6 Address                            LinkLayer-Addr      
 2001:201:1:1::34                         cc4e.246d.2038            

The following example shows the output of the show ipv6 neighbor inspectionstatistics command.

device(config)# show ipv6 neighbor inspection statistics
Total number of ND Solicit received      11
Total number of ND Advert received      29
Total number of Router Solicit received  20
Total number of ND dropped               6

The following example shows the ND inspection statistics of a VRF.

device(config-vrf-3)# show ipv6 neighbor vrf 3 inspection statistics
Total number of ND Solicit received      11
Total number of ND Advert received      29
Total number of Router Solicit received  20
Total number of ND dropped               6

The following example shows the output of the show ipv6 neighbor inspectionvlanvlan-number command.

device (config)# show ipv6 neighbor inspection vlan 2
IPv6 Neighbor inspection VLAN 2: Enabled
  Untrusted Ports : ethe 1/1/1 to 1/1/2
  Trusted Ports : ethe 1/1/3


The following example shows the details of the VLANs on which ND inspection is enabled for a VRF.

device (config-vrf-3)# show ipv6 neighbor vrf 3 inspection vlan 2
IPv6 Neighbor inspection VLAN 2: Enabled
  Untrusted Ports : ethe 1/1/1 to 1/1/2
  Trusted Ports : ethe 1/1/3


History
Release version Command history
08.0.20 This command was introduced.