show ipv6 raguard
show ipv6 raguard
{
counts
|
policy
}
{
name
|
all
}
show ipv6 raguard
whitelist
{
number
|
all
}
show ipv6 raguard
vlan
{
vlan-id
}
Privileged EXEC mode
Global configuration mode
The
show ipv6 raguard
counts command is applicable only when logging is enabled on the policy.
RA Guard Policies on VLANs in a Campus Fabric Configuration
Untrusted ports trap packets to the CPU and perform RA guard processing. For non-PE units, a trap rule is programmed directly on the unit where the ports are located. However, for PE units in a Campus Fabric (SPX) configuration, an untrust CB cascade rule may be created and configured for all CB SPX cascade ports.
A CB cascade rule is created in the following cases:
- RA guard is enabled on a VLAN with PE 'untrust' ports as members.
- RA guard is enabled on a VLAN with PE ports as members, and logging is enabled in the RA guard policy bound to the VLAN. In this case, the PE member ports can be configured as 'untrust', 'trust', or 'host'.
No CB cascade rule is created when the VLAN has CB ports but no PE ports as members.
The following example shows the RA guard drop or permit counts for all RA guard policies:
device# show ipv6 raguard counts all POLICY: policy1 DROPPED-host port: 1 DROPPED-whitelist: 4 DROPPED-prefixlist: 1 DROPPED-max pref: 3 PASSED-trusted port: 0 PASSED-untrusted port: 0 POLICY: policy2 DROPPED-host port: 1 DROPPED-whitelist: 0 DROPPED-prefixlist: 3 DROPPED-max pref: 1 PASSED-trusted port: 0 PASSED-untrusted port: 0
The following example shows the details of a RA guard policy p1:
device# show ipv6 raguard policy p1
policy:p1
whitelist:1
The following example shows all RA guard whitelists:
device# show ipv6 raguard whitelist all
whitelist #1 : 3 entries
permit fe80:db8::db8:10/128
permit fe80:db8::db8:5/128
permit fe80:db8::db8:12/128
The following example displays output for a VLAN.
device# show ipv6 raguard vlan 320 VLAN Policy ----- ------ 320 policy650 device#
When you use the
show ipv6 raguard command to display information on RA guard policies for a VLAN with member ports
that are part of an SPX system, the output indicates whether a CB cascade rule has
been created and, if so, to which SPX cascade ports it applies.
The following example shows that RA guard policy10 is applied to VLAN 1001 but logging is not enabled under the policy. As a result, no cascade-port rule has been created for the cascade ports in this SPX configuration.
device(config-if-pe-e1000-44/1/15)# show ipv6 raguard vlan 1001 VLAN Policy ----- ------ 1001 policy10 RA guard Cascade-port rule not created
The following example indicates an RA guard policy (policy20) with logging enabled is applied on VLAN 2001. The output shows the CB SPX cascade ports where it is applied.
device(config-vlan-2001)# show ipv6 raguard vlan 2001 VLAN Policy ----- ------ 2001 policy20 RA guard Cascade-port rule created for ports: 1/1/1 2/1/15 2/1/20 3/1/20