show ipv6 raguard
show ipv6 raguard
{
counts
|
policy}
{
name
|
all
}show ipv6 raguard
whitelist
{number
|
all
}show ipv6 raguard
vlan
{
vlan-id
}Privileged EXEC mode
Global configuration mode
The show ipv6 raguard
counts command is applicable only when logging is enabled for the
policy.
Untrusted ports trap packets to the CPU and perform RA guard processing. A trap rule is programmed directly on the unit where the ports are located.
The following example shows the RA guard drop or permit counts for all RA guard policies:
device# show ipv6 raguard counts all POLICY: policy1 DROPPED-host port: 1 DROPPED-whitelist: 4 DROPPED-prefixlist: 1 DROPPED-max pref: 3 PASSED-trusted port: 0 PASSED-untrusted port: 0 POLICY: policy2 DROPPED-host port: 1 DROPPED-whitelist: 0 DROPPED-prefixlist: 3 DROPPED-max pref: 1 PASSED-trusted port: 0 PASSED-untrusted port: 0
The following example shows the details of RA guard policy p1:
device# show ipv6 raguard policy p1
policy:p1
whitelist:1
The following example shows all RA guard whitelists:
device# show ipv6 raguard whitelist all
whitelist #1 : 3 entries
permit fe80:db8::db8:10/128
permit fe80:db8::db8:5/128
permit fe80:db8::db8:12/128