IPv6 Source Guard

You can use IPv6 Source Guard (IPSGv6) together with IPv6 Neighbor Discovery Inspection (NDI) on untrusted ports.

The RUCKUS implementation of the IPSGv6 technology supports configuration on a port and specific VLAN memberships on a port.

When IPSGv6 is first enabled, only DHCPv6 packets are allowed, while all other IPv6 traffic is blocked. IPSGv6 allows IPv6 traffic when the system learns IPv6 addresses via IPv6 DHCP snooping.

When IPSGv6 is enabled, the IPv6 user ACLs are not allowed to bind on the IPSGv6-enabled port or VLAN. To enable ACLs on the IPSGv6-configured port, you have to use SG ACLv6 and filters. Before binding SG ACLv6, SG ACLv6 should be enabled using sg-aclv6 enable; once enabled, save the configuration and reboot the switch for SG ACLv6 to take effect and be allowed to bind.

When a new IPv6 source binding entry on the port is created or deleted, an access-list with a permit filter for the IPv6 address is added or deleted. By default, if IPSGv6 is enabled without any IPv6 source binding on the port, an ACL that denies all IPv6 traffic is loaded on the port.